4 ms·
Digest should just die. It’s a terrible standard that makes it essential impossible to store passwords securely on the server.
by nmadden 5y ago
Digest should just die. It’s a terrible standard that makes it essential impossible to store passwords securely on the server.
- scottlamb 5y ago100% agree. It's like when you call into phone support and the person on the other end obviously can see your plaintext password. I'm working with IP security cameras, and the ONVIF standards [1] actually mandate Digest. I own cameras that only support HTTP Digest Authentication for RTSP. I'd tell the ONVIF folks this is dumb, but I don't want to pay $10,000/year for that privilege. [2] The only saving grace is that they aren't "real user" passwords, and you can isolate the cameras to a network segment where only the NVR can talk to them and vice versa. (And the NVR needs to keep the plaintext password anyway.) [1] https://www.onvif.org/profiles/specifications/ https://www.onvif.org/profiles/specifications/ [2] https://www.onvif.org/join-us/membership-levels/ https://www.onvif.org/join-us/membership-levels/
- duskwuff 5y agoDigest authentication made sense back when HTTPS was difficult and expensive to set up. Now that Let's Encrypt (and others!) have made HTTPS hosting more accessible, it's mostly pointless.
- LukeShu 5y ago"Digest" authentication was always bad, even back when HTTPS was difficult. It requires the server to store passwords in plaintext, rather than as hashes.
- duskwuff 5y agoDigest auth stores passwords on the server as plaintext; basic auth transmits passwords over the network as plaintext. Both are bad, but I feel like having the plaintext on the network is probably worse.
- LukeShu 5y agoFor sure. But "better than 'Basic'" is a much lower bar than "not bad". I was going to say that this problem is already noted in the very first RFC, that it was already known to be broken on day one; but on a closer reading I'm not sure that's actually true.
- nmadden 5y agoThe format that Digest uses to transmit passwords is not a lot better than plaintext. It’s a simple salted hash, which is easily brute-forced offline unless the password is strong.