3 ms·
Exactly, and use public key crypto: 1) Generate public/private key pair for user. 2) Send public key to client. 3) Encrypt PW on client, store as cookie. 4)
by bbb 18y ago
Exactly, and use public key crypto:
1) Generate public/private key pair for user.
2) Send public key to client.
3) Encrypt PW on client, store as cookie.
4) Store (user, private key) on your server.
5) Client now sends the encrypted PW whenever it is needed.
6) Server decrypts on demand, but does not store a local copy.
Since you never relinquish the private key this is pretty much unbreakable for spyware going through a client's cookies. (Nevermind key loggers...)