# Ember.js authentication with salted + hashed password

**URL:** <https://discuss.emberjs.com/t/ember-js-authentication-with-salted-hashed-password/5645>\
**Category:** Uncategorized\
**Created:** [June 13, 2014, 10:57am UTC](https://discuss.emberjs.com/t/ember-js-authentication-with-salted-hashed-password/5645 "2014-06-13T10:57:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![danie11am](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/danie11am/32/15886_2.png) [@danie11am](https://discuss.emberjs.com/u/danie11am)\
**Post date:** [June 13, 2014, 10:57am UTC](https://discuss.emberjs.com/t/ember-js-authentication-with-salted-hashed-password/5645/1 "2014-06-13T10:57:07Z")

</div>

Has anyone got good, simple, Ember.js authentication examples where the app would send hashed + salted passwords to server?

It seems that all the examples I could find do not employ hashed + salted passwords. I.e. in these examples passwords are sent from Ember.js app to the server in plain text.

---

<div class="post-metadata">

**Author:** ![bakura](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/bakura/32/4398_2.png) [@bakura](https://discuss.emberjs.com/u/bakura)\
**Post date:** [June 13, 2014, 2:29pm UTC](https://discuss.emberjs.com/t/ember-js-authentication-with-salted-hashed-password/5645/2 "2014-06-13T14:29:17Z")

</div>

I’m not sure to understand, as the JavaScript code is readable, you can’t really hash your password client-side as you would need to expose the salt.

The way I’m doing is using HTTPS only, sending the password in clear text for registration, hashing it on server. Then my server never returns anything to the client (not even the hashed password), and only communicate to my API using an OAuth2 token (I really recommend you to use Ember-Simple-Auth for that).

That’s the simplest workflow.

---

<div class="post-metadata">

**Author:** ![kylecoberly](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/kylecoberly/32/15828_2.png) [@kylecoberly](https://discuss.emberjs.com/u/kylecoberly)\
**Post date:** [June 13, 2014, 5:03pm UTC](https://discuss.emberjs.com/t/ember-js-authentication-with-salted-hashed-password/5645/3 "2014-06-13T17:03:13Z")

</div>

Another thing I’ve done is used an intermediary server that just handles encryption and proxies the server requests for you. But @bakura is correct, you really can’t use a hashing mechanism client-side with any efficacy- just encrypt the communication channel. +1 for simple-auth also.

---

<div class="post-metadata">

**Author:** ![danie11am](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/danie11am/32/15886_2.png) [@danie11am](https://discuss.emberjs.com/u/danie11am)\
**Post date:** [June 14, 2014, 2:34am UTC](https://discuss.emberjs.com/t/ember-js-authentication-with-salted-hashed-password/5645/4 "2014-06-14T02:34:58Z")

</div>

Thanks both. Yes I do plan to use HTTPS and a token after registration/login. However I still thought that sending password in the clear during sign-up/login isn’t good idea, even over HTTPS.

I used to implement hashed + salted password authentication for a native mobile app. Referencing on something like this: [http://www.thebuzzmedia.com/designing-a-secure-rest-api-without-oauth-authentication/](http://www.thebuzzmedia.com/designing-a-secure-rest-api-without-oauth-authentication/) That’s why I asked the question.

After seeing your responses I did more research. Indeed it appears that plain text over HTTPS is the norm and considered secure enough. So I’ll go with that.

For future references though, I think there may still be cases when additional encryption/hashing is beneficial. There is [a good discussion here](http://security.stackexchange.com/questions/46529/is-ssl-secure-enough-for-a-rest-api-has-anyone-used-pgp-or-aes-to-encrypt-the), one of the linked [youtube video](http://www.youtube.com/watch?v=4s0rZgcATrg) is a presentation from OWASP and is eye-opening, titled “OWASP AppSecUSA 2012: Reverse Engineering Secure HTTP API’s With an SSL Proxy”.

---

<div class="post-metadata">

**Author:** ![7sedam7](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/7sedam7/32/9606_2.png) [@7sedam7](https://discuss.emberjs.com/u/7sedam7)\
**Post date:** [October 1, 2014, 7:38am UTC](https://discuss.emberjs.com/t/ember-js-authentication-with-salted-hashed-password/5645/5 "2014-10-01T07:38:17Z")

</div>

You can use some asymmetric encryption and decryption (for example RSA). You give client public\_key and encrypt the password with it and on server side you can decrypt it with servers secret\_key that only server knows about.

---

<div class="post-metadata">

**Author:** ![RitikJaiswal75](https://sea1.discourse-cdn.com/flex019/user_avatar/discuss.emberjs.com/ritikjaiswal75/32/18100_2.png) [@RitikJaiswal75](https://discuss.emberjs.com/u/RitikJaiswal75)\
**Post date:** [June 15, 2023, 9:09am UTC](https://discuss.emberjs.com/t/ember-js-authentication-with-salted-hashed-password/5645/6 "2023-06-15T09:09:41Z")

</div>

Even though the password is being sent over HTTPS, it needs to be encrypted is what I think. To get a better idea of this practice I referred to this: [OPAQUE: The Best Passwords Never Leave your Device](https://blog.cloudflare.com/opaque-oblivious-passwords/)

But, I also agree on the part of salts being exposed in this case we can use RSA encryption but doing it over a browser might be very costly. (I am not even sure if it is possible. Accessing RSA keys in frontend).
