Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Mon, 06 Nov 2000 21:21:01 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1 2 3 4 5 6 7 8 9  Groups: php.general 
Request: Send a blank email to php-general+get-23980@lists.php.net to get a copy of this message
=== scottrus@ipass.net escribia (Mon, Nov 06, 2000 at 03:21:58PM -0500): > Yes, this is typically secure enough for most intranet and low grade sites > IMHO. Obviously if you're going to be doing transactions or need to eliminate > man in the middle attacks then the only way to go is SSL. Well, for me a base64 encoded password is as good as no password at all, sincerely. Maybe I'm just too sensitive about the subject, I know of a site where big bucks cruise the wires every day along with clear text passwords. Gives me the gooseflesh. > To clarify the snipped text shown below from my original post, I think it's easier > to swipe the logon page and modify the form input than to setup something that > sends a 401 response (is that right code for browserauth?) back to the target server > a cracker is trying to get into. It's also pretty easy to sniff the base64 strings and unravel them into the original thing, isn't it ? And you don't even have to forge forms and stuff. > > -- Scott > Manuel Garcia > On Mon, Nov 06, 2000 at 08:04:25PM +0100, Manuel Enrique Garcia Cuesta wrote: > > > > > > === scottrus@ipass.net escribia > > (Mon, Nov 06, 2000 at 10:18:57AM -0500): > > > > > Also, regarding user auth, I think the best way is to use basic browser > > > authentication > > > through php. It's a bit more complex to write in some cases but it helps > > > eliminate > > > people swiping the login form and trying to hack it to by pass the auth check. > > > > It surely cannot be that, but I have to ask. By basic > > browser authentication you mean letting the browser base64-scramble > > user+password ? > > > > > > > > -- Scott > > > > Manuel Garcia > > >

« previous php.general (#23980) next »