4 ms·
It depends on your login process. For signing up to a site, you generally will want/need HTTPS. For login, what is transported on the wire can be a hash or so
by theonewolf 14y ago
It depends on your login process. For signing up to a site, you generally will want/need HTTPS.
For login, what is transported on the wire can be a hash or some form of the password which is no longer plaintext.
Thus, _logins_, may not need HTTPS protection.
It depends on implementation.
As a quick path for HackerRank.com to fix, I proposed HTTPS which is already implemented, rather than modifying web app logic.
- paulgb 14y agoNo, encrypting client-side is still vulnerable to a MITM attack. The MITM simply removes the code to encrypt the password from the website.
- drivebyacct2 14y agoIf you transmit the hash, it's either going to be unsalted, or the salt will have been sent ahead of time, leaving it open to being brute forced. Further, it's still a huge MITM attack because if you can login to whatever.com with theonewolf/HASHOFYOURPASSWORD then I can sniff that... and login as theonewolf/HASHOFYOURPASSWORD too.