- they ensure that the backend application never sees your password in plaintext , and prevent the worst case scenario of a plaintext data dump
- password hashing is CPU intensive by design, and pushing that work to the client means you can have them do the work and increase # of iterations far more aggressively
but fundamentally still leaves users vulnerable compared to other approaches. For example, client-side hashed passwords can still be phished, and are not domain-bound like Passkeys are.I think an alternative approach would be to accept a certain risk that credentials can be stolen and improve the ways in which stolen credentials can be revoked.
& after trying to solve those problems, there's still mTLS or passkeys that offer better security anyways.
A password manager may be extra work but it's pretty minimal nowadays. On Chrome, it will automatically offer to generate passwords in signups and save them. If you add a Google, it will sync passwords between devices. Sure, everyone may not want this, but it's easy for less tech savvy people and still fairly secure
Still better than plain text but nothing stopping a determined hacker.
Anything else is just encrypting the transport, which we already do with HTTPS.
Otherwise there is the ongoing work to of passkeys.