3 ms·
>In fact, with my current startup's application, the user's Password would never even _leave_ the client machine. Javascript would perform an MD5 hash, and the
by kule 16y ago
>In fact, with my current startup's application, the user's Password would never even _leave_ the client machine. Javascript would perform an MD5 hash, and the server treats that as the client's password.
In some respects it makes you wonder why browsers never had this natively in the first place - why should a third-party need to know my password when it could just send a hash instead?
- meinhimmel 16y agoThat's an interesting question, and it may have to do with the age of Javascript. It's really only been around for 15 years now according to Wikipedia. At that point, the web was already starting to expand quickly, and browser support has typically been shoddy with new technology.
- pieter 16y agoBecause if you just send the MD5, others can log in as you when they know the MD5, which they can just sniff. It doesn't gain anything in security, except for not knowing your actual password.
- pornel 16y agoYou can send `nonce + MD5(nonce MD5(username realm pass))`, and then it's not sniffable.
- pieter 16y agoAt that point, the server will have to have received the MD5(username realm pass) at least once in order to verify the hash. You're better off not building your own schemes and instead trust existing solutions like SSL.
- antileet 16y agoThat wasn't the reason for Hashing the password before sending it to the server. It's common knowledge that a lot of people use the same password for many lower-rung services. So if I send MD5 ( Password + Salt String), even if the attacker sniffs this and logs on as the user, the original password string isn't compromised, despite the fact that the salt string is publicly visible.
- pornel 16y agoThey do have it. Digest HTTP authentication has MD5-based challenge-response, but (just like any JS solution) it's not secure when attacker can modify request/response.
- antileet 16y agoThe way I see it - forms, multipart-post, etc came first, and then people found a way to abuse this to create login forms. Actual "HTTP Authentication" does a Base64 encode to make it Unreadable to the naked eye. It would be nice if I could tell the browser to hash the data before sending it to the server like so: <input type="password" name="secret" hash="yes" />