>
You have responded in the wrong place.I'd say it was the correct place.
>If the client-side hashing were not performed at all, it would still be impossible to correlate user passwords with other passwords in database dumps.
Right—assuming the passwords are gleaned from the database, for example. However, the entire point was that there's no need to do correlation of anything stored server-side in the first place when an attacker is reading the raw user password input as it comes off the wire. Client-side hashing brings this scenario roughly to parity with the protections afforded at the database level.
Database compromise? Server-side salt/hash.
Limited-scope server runtime or network-level compromise? Client-side salt/hash.
Again, it depends on the nature and scope of the exploit.
>But claim P1 is nonsense. It is true that user passwords on the server can't be correlated with other passwords in database dumps. But client-side hashing has nothing to do with that. If the client-side hashing were not performed at all, it would still be impossible to correlate user passwords with other passwords in database dumps.
Not when you're in possession of the user's non-hashed raw password input. That's correlation city, even in the strict literal sense you're talking here.
>It's correct that -- if the method of learning a user's password is to read their active TLS connection with the server -- the password learned by that method will not be useful on other third-party websites.
Then you finally cede that client-side hashing has value.
>Why are we describing an entirely spurious claim as "clear"?
I fail to see how it's spurious when we've established countless times throughout this thread that client-side hashing has value.
Do you think client-side hashing has value? Because your original comments seemed to emphatically deny that.