Re: At what layer to hash a password

Chris Travers <[email protected]>
Newsgroups gmane.comp.security.web-applications
Message-ID <[email protected]>
On Sat, Jun 26, 2010 at 10:02 AM, Javier Bassi <[email protected]> wrote:
> If I'm not wrong, some forums like vBulletin when you login, they send
> the password in md5 (using javascript). Thats better than sending it
> in plain/text.

Howso?  In either case you have an observable value which can be
submitted to the web server to gain access.

Obfuscation != security.

Either use SSL or a challenge/response authentication system of some
sort.  There really isn't a substitute beyond this.

Best Wishes,
Chris Travers



This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now! 
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.