Does this imply the client doing the encryption? I.e. the client creates a key pair and sends the public key to the server?
It sounds good but the challenge, as always, is the infrastructure. I think it would be great if I had a single personal private key from which I could issue chained keys for each domain where I have an account. But imagine managing this across desktops, browsers, phones, game systems, etc. ...
My intent was that the server should still be responsible for scrambling the password as usual. - My question is only about changing the algorithm server-side.
It sounds good but the challenge, as always, is the infrastructure. I think it would be great if I had a single personal private key from which I could issue chained keys for each domain where I have an account. But imagine managing this across desktops, browsers, phones, game systems, etc. ...