Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | scottrus at ipass dot net | Date: | Tue, 07 Nov 2000 06:05:26 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-24054@lists.php.net to get a copy of this message | ||
On Mon, Nov 06, 2000 at 10:21:01PM +0100, Manuel Enrique Garcia Cuesta wrote:
> === scottrus@ipass.net escribia
> (Mon, Nov 06, 2000 at 03:21:58PM -0500):
>
> > Yes, this is typically secure enough for most intranet and low grade sites
> > IMHO. Obviously if you're going to be doing transactions or need to eliminate
> > man in the middle attacks then the only way to go is SSL.
>
> Well, for me a base64 encoded password is as good as no
> password at all, sincerely. Maybe I'm just too sensitive about
> the subject, I know of a site where big bucks cruise the wires
> every day along with clear text passwords. Gives me the gooseflesh.
Of course. I'm not advocating that base64 encoded passwds are good enough
for ever application. Obviously when doing any kind of finance transacton,
for example, only SSL + encrypted text will do.
>
> > To clarify the snipped text shown below from my original post, I think it's easier
> > to swipe the logon page and modify the form input than to setup something that
> > sends a 401 response (is that right code for browserauth?) back to the target server
> > a cracker is trying to get into.
>
> It's also pretty easy to sniff the base64 strings and
> unravel them into the original thing, isn't it ? And you don't
> even have to forge forms and stuff.
>
Yes, it is. But the original problem being described was not how to avoid
the man in the middle with a sniffer but instead how to stop the much more
direct practice of swiping HTML source and directly feeding the auth cgi
junk. My response to that is don't do that. Use 401 browser auth instead. If
you need something better than base64 encoding then add SSL to the mix.
--
Scott