Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | Manuel Enrique Garcia Cuesta | Date: | Mon, 06 Nov 2000 21:21:01 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23980@lists.php.net to get a copy of this message | ||
=== scottrus@ipass.net escribia
(Mon, Nov 06, 2000 at 03:21:58PM -0500):
> Yes, this is typically secure enough for most intranet and low grade sites
> IMHO. Obviously if you're going to be doing transactions or need to eliminate
> man in the middle attacks then the only way to go is SSL.
Well, for me a base64 encoded password is as good as no
password at all, sincerely. Maybe I'm just too sensitive about
the subject, I know of a site where big bucks cruise the wires
every day along with clear text passwords. Gives me the gooseflesh.
> To clarify the snipped text shown below from my original post, I think it's easier
> to swipe the logon page and modify the form input than to setup something that
> sends a 401 response (is that right code for browserauth?) back to the target server
> a cracker is trying to get into.
It's also pretty easy to sniff the base64 strings and
unravel them into the original thing, isn't it ? And you don't
even have to forge forms and stuff.
>
> -- Scott
>
Manuel Garcia
> On Mon, Nov 06, 2000 at 08:04:25PM +0100, Manuel Enrique Garcia Cuesta wrote:
> >
> >
> > === scottrus@ipass.net escribia
> > (Mon, Nov 06, 2000 at 10:18:57AM -0500):
> >
> > > Also, regarding user auth, I think the best way is to use basic browser
> > > authentication
> > > through php. It's a bit more complex to write in some cases but it helps
> > > eliminate
> > > people swiping the login form and trying to hack it to by pass the auth check.
> >
> > It surely cannot be that, but I have to ask. By basic
> > browser authentication you mean letting the browser base64-scramble
> > user+password ?
> >
> > >
> > > -- Scott
> >
> > Manuel Garcia
> >
>