Re: Security Questions
| From: | Rasmus Lerdorf | Date: | Sun, 20 Aug 2000 23:53:36 +0000 |
| Subject: | Re: Security Questions | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12693@lists.php.net to get a copy of this message | ||
Well, they are base64 encoded, but that is as close to plaintext as you
can get. Decoding it is trivial. Until more browsers start supporting
digest auth, you are stuck with plaintext auth if you don't go to SSL.
-Rasmus
On Mon, 21 Aug 2000, Simon Edwards wrote:
> Mark Lo wrote:
> > I would like to know how secure is $PHP_AUTH_USER and $PHP_AUTH_PASSWD.
> > Can third party observe it while in transmit ??
>
> I believe that those to vars are set using HTTP authentication, and yes
> they are sent as plain text. You could use SSL though. Another
> interesting solution that doesn't involve SSL is used by PHPLIB. They
> use challenge/response auth using javascript to do MD5 on the client
> side. Very clever I thought.
>
>
> --
> Simon Edwards
>
> Animated Design, Melbourne
> http://www.animated.net.au/ Ph: (03) 98850990
>
>