4 ms·
We implemented http digest authentication (http://en.wikipedia.org/wiki/Digest_access_authentication http://en.wikipedia.org/wiki/Digest_access_authentication)
by revelate 17y ago
We implemented http digest authentication (http://en.wikipedia.org/wiki/Digest_access_authentication http://en.wikipedia.org/wiki/Digest_access_authentication) in our application for the following reasons:
- We needed to securely authenticate users connecting with browsers and rss readers without ssl.
- We needed an encryption algo that we could implement in javascript so as to provide reasonably secure login without ssl.
Is there any way to do the above while storing bcrypt passwords on the server? Does using bcrypt in these scenarios force you to use https and pass full text passwords to the server?