Re: Security Questions

From: Date: Sun, 20 Aug 2000 23:40:46 +0000
Subject: Re: Security Questions
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-12692@lists.php.net to get a copy of this message
Mark Lo wrote: > I would like to know how secure is $PHP_AUTH_USER and $PHP_AUTH_PASSWD. > Can third party observe it while in transmit ?? I believe that those to vars are set using HTTP authentication, and yes they are sent as plain text. You could use SSL though. Another interesting solution that doesn't involve SSL is used by PHPLIB. They use challenge/response auth using javascript to do MD5 on the client side. Very clever I thought. -- Simon Edwards Animated Design, Melbourne http://www.animated.net.au/ Ph: (03) 98850990

« previous php.general (#12692) next »