4 ms·
"in the clear over ssl instead of hashing them"? am i missing something here? is ssl insecure? is there some way to charge a credit card that doesn't actually
by nsfmc 15y ago
"in the clear over ssl instead of hashing them"? am i missing something here?
is ssl insecure? is there some way to charge a credit card that doesn't actually involve sending the number to anybody?
- scarlson 15y agoThe same way you're able to login to News.YC without sending your actual password via the intertubes.
- dpritchett 15y agoSo some sort of public-key cryptography? I didn't realize that the HN login page didn't send a password on a login.
- xsmasher 15y agoI'm not sure I understand you; CC numbers are not passwords. You can't salt and hash them on one end and then confirm on the other end; you need to send the whole number if you expect to process a charge against it.
- JoachimSchipper 15y agoYou mean "not at all"? Just fire up a packet sniffer...
- jonknee 15y agoBut you do send your actual password... The hashing occurs on the server. Also, this has nothing to do with credit cards. They are not passwords.
- tzs 15y agoThe HN login sends your password over the internet. It doesn't even use SSL. It is in the clear, readily visible to anyone able to run a packet sniffer on your traffic.