3 ms·
Something cool that I didn't highlight since it's not the main point: The web UI uses the OPAQUE protocol to log in/store passwords, so your password is never
by nitnelave 4y ago
Something cool that I didn't highlight since it's not the main point:
The web UI uses the OPAQUE protocol to log in/store passwords, so your password is never sent to the server (it instead stores just enough information for you to provide a cryptographic zero-knowledge proof that you have the correct password).
It's a bit undermined by the fact that LDAP binds use plaintext passwords, but I thought it would be cool to implement :)
- hangonhn 4y agoYeah the plaintext password thing sucks but you can mitigate that with LDAPS so it talks over a secure socket. The other choice you have is to use Kerberos to do the authentication. Also, thanks for the tip about OPAQUE. Going to go check it out.
- throw0101a 4y agoAn updated draft was just released last week: * https://datatracker.ietf.org/doc/html/draft-irtf-cfrg-opaque https://datatracker.ietf.org/doc/html/draft-irtf-cfrg-opaque
- jdswain 4y agoI’ve used SRP on a few projects, including for a large bank for the log in from their counter system. Once you get the algorithm sorted out it’s quite simple and it feels a whole lot better than some of the password storage systems I have seen (and still do see) implemented. I’ll have to have a look at OPAQUE, which according to Wikipedia is a newer alternative to SRP. Edit: Just noticed that there are quite a few more systems using these types of algorithms, including Apple HomeKit.
- hyc_symas 4y agoYou could use an LDAP SASL Bind instead, using any of a variety of strong authentication mechanisms then without plaintext passwords.