  1. The answer is, yes, but it doesn't provide much advantage,
  2. since now an attacker who learns the hash of p doesn't need to learn p.
  3. The first statement is not true.
  4. If there was some dictionary attack using the password,
  5. it'd work just as well using the hash of the password.
  6. The third one is also not true.
  7. The server doesn't need to invert the hash, and a shared key can be established
  8. just like before.
  9. The fourth is not true.
  10. If there was a serious security vulnerability in this protocol,
  11. It would exist in the original protocol as well.