Re: Security Questions
| From: | Simon Edwards | Date: | Sun, 20 Aug 2000 23:40:46 +0000 |
| Subject: | Re: Security Questions | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12692@lists.php.net to get a copy of this message | ||
Mark Lo wrote:
> I would like to know how secure is $PHP_AUTH_USER and $PHP_AUTH_PASSWD.
> Can third party observe it while in transmit ??
I believe that those to vars are set using HTTP authentication, and yes
they are sent as plain text. You could use SSL though. Another
interesting solution that doesn't involve SSL is used by PHPLIB. They
use challenge/response auth using javascript to do MD5 on the client
side. Very clever I thought.
--
Simon Edwards
Animated Design, Melbourne
http://www.animated.net.au/ Ph: (03) 98850990