4 ms·
Of the sites which don't send passwords in the clear, any idea how many are just obfuscating? (Xor, base64, etc).
by jbert 17y ago
Of the sites which don't send passwords in the clear, any idea how many are just obfuscating? (Xor, base64, etc).
- tptacek 17y agoAnything that uses Javascript to encrypt passwords is almost certainly just obfuscating passwords, in effect. Meebo was an example, awhile ago.
- jbert 17y agoI guess you could send out a unique session key with the page, have the JS run AES or similar. Wait, stop, crypotime. I'm appear to be trying to design a protocol for secret exchange. I should just go and do some reading instead. Do you know if there's any value in http digest auth these days? It's deployed in http clients (but only with md5 algo?) and I think it requires the server to store single-hash-of (salt,realm,pw) which you've eloquently pointed out in the past is a bad idea (single-hash of pw is vulnerable to bruteforce since hashes are fast). My current thinking is that http basic auth over ssl would be preferred to http digest (as an auth method widely, natively supported by http clients), since it avoids pw in plaintext and allows server to store stronger hash (e.g. stretched sha-256, bcrypt) for pw.
- tptacek 17y agoThe problem isn't crypto. The problem is that Javascript in the DOM model runs crypto code in an environment where you can't be sure what any symbol means, because any of a dizzying variety of page components or updates sourced on-site and off, under SSL and (most likely) not, could have modified them.