Ask HN: Is this the right way to create a login?
When the user opens a login page, the server creates a session and sends a random string along with the login page. On the client side, JS computes the salted hash of entered password (salt = username), then appends the random string as salt and computes hash again. Then sends this hash to us via post.
The server matches received hash against hash of (stored hash+random string that we sent).
So is this method secure? If not, what can we do to improve it?