This is how it is done for 20 years (by those who truly care about the users).
As many have said before, transmitting the hash simply turns the hash into the password itself. Anyone who has your hash, has your password.
The biggest reason for hashing is that, even if an attacker gets access to the hashed passwords, they still can't use them to log in. Client-side hashing completely and utterly undoes that benefit.
Passwords in transit should be protected by SSL. Not a hash.
Most interestingly, it solves the problem where the server may not be trusted. I see how this would have protected against the Facebook problem.
I'm curious, have any major websites you're aware of adopted SCRAM as a best security practice? It feels kind of like overkill, since generally the server is considered to be trusted... but at the same time, it would definitely prevent accidental logging.
It was my understanding yhat my password, on a properly configured login page, never left my browser, much less crossed multiple machines that had the ability to read it.
Unfortunately, we are in 2019 and client-side hashing is rare because people use SSL instead.
One can argue that company like Facebook that is well stocked with tech resources should have figured this out already but here we are.
Replace the outer H with a proper key derivation function for extra credits.
This avoids sending any secret value over to the server, so no server side logging will cause a problem.
When the login screen loads, server sends the server time so with reasonably fast internet, the client can estimate the server time. Let's call the estimated current server time t. On login, client sends H(H(p)+t) with t. Now the server can compute H(H(p)+t) with the t from the client and verify if the hash match and also check if t is within few seconds of the current server time.
This way if any data that goes over the network leaks for gets logged, it'll only be valid for few seconds. Also salting before hashing should go somewhere in there but it'll make it a bit more complicated.