Hacker News new | past | comments | ask | show | jobs | submit login

What is the benefit of PAKE over this: https://datatracker.ietf.org/doc/html/rfc2289



PAKEs are secure over insecure channels. Also I'm pretty sure for RFC2289 the server stores a password equivalent. If you neither care about creating an encrypted session nor being secure over an insecure channel, then you should use SCRAM. With SCRAM, the server stores a password hash equivalent. Meaning an attacker needs to crack the password before they can login as them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: