[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [WEB SECURITY] username & pw in clear-text through SSL considered safe?
- From: "Martin O'Neal" <martin.oneal@xxxxxxxxxxxx>
- Subject: RE: [WEB SECURITY] username & pw in clear-text through SSL considered safe?
- Date: Wed, 18 Jun 2008 07:27:03 +0100
> I'm not sure if hashing the password
> on the client side would be best practice
> (anyone have a strong opinion?) but it
> seems effective.
The problem is that it is not effective, just cosmetic. It doesn't buy
you anything (other than a false sense of security).
If someone has compromised your SSL, they can change whatever you put
inside it. In this example, all an attacker has to do is amend the
javascript as it goes past and make it send the cleartext auth.
Martin...
----------------------------------------------------------------------------
Join us on IRC: irc.freenode.net #webappsec
Have a question? Search The Web Security Mailing List Archives:
http://www.webappsec.org/lists/websecurity/
Subscribe via RSS:
http://www.webappsec.org/rss/websecurity.rss [RSS Feed]
Join WASC on LinkedIn
http://www.linkedin.com/e/gis/83336/4B20E4374DBA
Brought to you by http://www.webappsec.org
Search this site
|