3 ms·
From the article: "Any attacker who could swipe an unencrypted secret can, with almost total certainty, intercept and alter a web request. Intercepting request
by hammerdr 15y ago
From the article:
"Any attacker who could swipe an unencrypted secret can, with almost total certainty, intercept and alter a web request. Intercepting requests does not require advanced computer science. Once an attacker controls the web requests, the work needed to fatally wound crypto code is trivial: the attacker need only inject another <SCRIPT> tag to steal secrets before they're encrypted."
This is strictly true from the perspective of cryptography. Crypto is always concerned with the strength of crypto from a mathematics point of view.
However, much of that worldview falls down in the real world. In the case of hashing a password before it goes over the wire (even the simplest salt-free MD5), which is crypto-logically naive and "considered harmful," you are providing a general barrier for people that are FireSheeping in a cafe. Many would-be attackers are thwarted by what crypto-nerds would see as silly.
In general, the weakest point of crypto in today's world is the human element. RSA Security got hacked not because the algorithm was weak but because someone installed a back door in RSA's network for the hackers. Once you get passed the point where it is more effective to attack sideways than head-on, the crypto has done all it can do.
That being said.. just use SSL. It moves that gauge enough that anyone trying to get your users' information isn't going to bother direct attacks.
Edit:
What I meant by the 'salt-free' MD5 is that of a challenge-handshake response. The challenge is sent by the server and the client responds with md5(pw+challenge). The salt would otherwise need to be sent in an insecure manner that would provide only marginal more security than a challenge-handshake. This was unclear and I apologize.
- dchest 15y agoWhat barrier? If you're sending password hash over the wire, and the server allows access based on this hash, the hash is essentially the password. Firesheep, BTW, steals cookies, not passwords.