password to the server? but a hashed version?
No, https is solid
yes, but the server might not be
If you have a MitM, they can intercept everything anyway
Then you can't trust it with your hashed password either
yes but they would have access to that service only, not the plaintext password to try to use it against other services
yes but in case my server gets compromised, you would only see hashed passwords go through, not plaintexts
Обсуждают сегодня