is an old authentication protocol that's still active in almost every domain. It works via Challenge-Response: the server sends a challenge, the client encrypts it with the password's Hash.
- No full Mutual Authentication — the client doesn't really verify the server's identity.
- Vulnerable to Relay: an attacker forwards your authentication to another server on your behalf.
- The Hash is equivalent to the password — hence .