Re: Unofficial PEAR meeting summary

From: Date: Fri, 07 May 2004 05:53:34 +0000
Subject: Re: Unofficial PEAR meeting summary
References: 1 2 3 4 5 6 7 8 9  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-28925@lists.php.net to get a copy of this message
On Thu May 06, 2004 at 10:3433PM +0200, Cipriano Groenendal wrote: > If you look at Auth/Container/PEAR.php, you'll see that the Auth package > uses an RPC call to get userinfo. Within taht is the md5sum of the pass, > which is compared to a locally md5'd password string. Wether this is by > design, or a bug, in cases like this it's quite cool :) That's definitively a bug! If I don't hear any *good* objections, I'll remove the password from the return value of user.info at the weekend. > However, we are not passing anything in the open, except for perhaps and > md5sum of the password. This could be considered secure by most > people , > unless you're really paranoid :) I don't think one needs to be paranoid to consider this insecure. -- - Martin Martin Jansen http://martinjansen.com/

« previous php.pear.dev (#28925) next »