And we do implement a PAKE.
For reference, I explained our approach a bit in this comment [0], and mentioned how we'll have more documents and diagrams available in the near future to explain it some more. Will explain it in more detail here (but be warned, it's still missing some steps and may seem a little convoluted to follow):
--Sign up--
1. user signs up and client generates a random seed in memory
2. client takes user's seed and inputs it through HKDF to derive a Diffie-Hellman key pair
3. client inputs user's password once through Scrypt, and then twice through HKDF to derive 2 values: password token & password-based encryption key
4. client encrypts user's seed from step 1 using password-based encryption key from step 3
5. client sends server the user's public DH key, password-encrypted seed, and password token for storage
--Sign in--
1. user inputs username and password
2. client inputs password once through Scrypt, and then twice through HKDF to derive 2 keys: password token & password-based encryption key
3. client sends server password token
4. server verifies password token matches stored token, and sends client a random message encrypted to the client's public DH key that was stored at sign up, along with the password-encrypted seed
5. client decrypts password-encrypted seed using password-based encryption key from step 2
6. client takes user's seed and inputs it through HKDF to derive DH key pair
7. client uses private DH key to decrypt random message from step 4 and sends plaintext message to server
8. client is now authenticated
Overall this approach is somewhat similar to Firefox's approach with Firefox Sync [1]