> Hash based challenge-response authentication does require the server to know the plain password.
Not true. Read up on HTTP Digest authentication. It's described in RFC2617.
Not true. Read up on HTTP Digest authentication. It's described in RFC2617.
</troll>