Re: Fwd: Hash for data in transit

Robert Hajime Lanning <[email protected]>
Newsgroups gmane.comp.security.web-applications
Message-ID <[email protected]>
You can hash the form data, then encrypt the hash with a shared transaction
key given to the user via a capcha type of method.

Basically you sign the form data using a capcha phrase as the random
shared per transaction key.  Just make sure the whole transaction uses
SSL/TLS of appropriate strength.

That would prove against tampering in transit, twice over.  Once via the
SSL/TLS and second via the internal signing.

On Tue, Jul 27, 2010 at 7:42 AM,  <[email protected]> wrote:
> Saleh,
>
> Thanks for the feedback. Our team is still trying different things to comply with this
> security requirement. Trying to find a solution to verify the integrity without opening
> more vulnerabilities with the solution. Any additional suggestions are welcomed.
>
> Thanks.

-- 
And, did Galoka think the Ulus were too ugly to save?
                                         -Centauri



This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now! 
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.