Exclusively for TechExams members for Infosec Boot Camps starting before April 30, 2026
ninjaz wrote: Since you don't send the actual password over the wire how does the server know how to compare the same hash as the client provided? Does the client machine take the password the user provided and hash it and then send that hash value to the server and compare that hash value with the one that the server has stored? If thats the case, couldn't someone use a replay attack with the same hash value as the user and get authenticated to the server and user those credentials?
ninjaz wrote: Also, what if a user wants to change their password to something else, wouldn't that password be sent across the wire to be stored on the server?
Exclusively for TechExam members. Applies to boot camps starting before April 30, 2026.