Re: Fwd: Hash for data in transit
Robert Hajime Lanning <[email protected]>
| Newsgroups | gmane.comp.security.web-applications |
|---|---|
| Message-ID | <[email protected]> |
You can hash the form data, then encrypt the hash with a shared transaction key given to the user via a capcha type of method. Basically you sign the form data using a capcha phrase as the random shared per transaction key. Just make sure the whole transaction uses SSL/TLS of appropriate strength. That would prove against tampering in transit, twice over. Once via the SSL/TLS and second via the internal signing. On Tue, Jul 27, 2010 at 7:42 AM, <[email protected]> wrote: > Saleh, > > Thanks for the feedback. Our team is still trying different things to comply with this > security requirement. Trying to find a solution to verify the integrity without opening > more vulnerabilities with the solution. Any additional suggestions are welcomed. > > Thanks. -- And, did Galoka think the Ulus were too ugly to save? -Centauri This list is sponsored by Cenzic -------------------------------------- Let Us Hack You. Before Hackers Do! It's Finally Here - The Cenzic Website HealthCheck. FREE. Request Yours Now! http://www.cenzic.com/2009HClaunch_Securityfocus --------------------------------------