Re: Unofficial PEAR meeting summary
| From: | Martin Jansen | Date: | Fri, 07 May 2004 05:53:34 +0000 |
| Subject: | Re: Unofficial PEAR meeting summary | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-28925@lists.php.net to get a copy of this message | ||
On Thu May 06, 2004 at 10:3433PM +0200, Cipriano Groenendal wrote:
> If you look at Auth/Container/PEAR.php, you'll see that the Auth package
> uses an RPC call to get userinfo. Within taht is the md5sum of the pass,
> which is compared to a locally md5'd password string. Wether this is by
> design, or a bug, in cases like this it's quite cool :)
That's definitively a bug! If I don't hear any *good* objections, I'll
remove the password from the return value of user.info at the weekend.
> However, we are not passing anything in the open, except for perhaps and
> md5sum of the password. This could be considered
secure by most
> people ,
> unless you're really paranoid :)
I don't think one needs to be paranoid to consider this insecure.
--
- Martin Martin Jansen
http://martinjansen.com/