It still doesn't prevent users from being stupid w.r.t. writing down passwords, but it at least presents users with reasonably secure logins that are relatively easy to remember.
It still doesn't prevent users from being stupid w.r.t. writing down passwords, but it at least presents users with reasonably secure logins that are relatively easy to remember.
And by plain-text, I mean the server receives information that could then be used to authenticate later.
For instance, if you send the sha of a password, and then store the sha of the sha, you're still sending the password in plaintext, it's just that it's not the password the user entered.
This method is no less secure than the standard "client sends server password over HTTPS" scheme.
... and how do you set up a secure connection without a pre-existing password?
Your solution has a chicken-and-egg problem.
SRP does.
[0] http://en.wikipedia.org/wiki/Secure_Remote_Password_protocol
[0] http://en.wikipedia.org/wiki/Secure_Remote_Password_protocol