Quote:
Originally Posted by Paul M
I hope you are using https on your site, otherwise you are transmitting plaintext paswords over the internet, generally not a good idea.
|
As far as I know, even if you send md5 hashed password over an http connection, an hacker could intercept it and remove the javascript md5 function on the client side (with Chrome it's really easy). This way the md5 password will be directly sent to the server and the hacker would gain access, so there's no big difference but yeah it's still better to not send plain text password.