Newer versions of MariaDB (a MySQL database server fork) have a new password based auth scheme called “ed25519”. The docs are very sparse regarding how it works and what it does.
What is the value stored in the database? How is it generated from the password? What is the value sent by the client to the server on login? How is it generated from the password? Is the scheme secure to use without TLS? How resistant is it against password dumps? What is the correct full name of this auth scheme? Is it used by anything else besides MariaDB? Are there other implementations?