25 ms·
Take a look at the paper "Dos and Don'ts of Client Authentication on the Web" by Kevin Fu et al. [1] You should respect your users and always transmit their
by mdakin 19y ago
Take a look at the paper "Dos and Don'ts of Client Authentication on the Web" by Kevin Fu et al. [1]
You should respect your users and always transmit their passwords over an SSL connection during the authentication process. Also only keep a hash of the password on your server. People tend to recycle passwords and by following those two recommendations you help them out quite a bit.
If you follow the paper's advice and mint a Fu Cookie it will have a finite lifetime and contain neither the user's password nor any other sensitive info. Thus for many applications it is not that bad to send it unencrypted over the network.
[1] http://pdos.csail.mit.edu/papers/webauth:tr.pdf http://pdos.csail.mit.edu/papers/webauth:tr.pdf
- jsjenkins168 19y agoExcellent, this is exactly what I was looking for. Thanks.
- mdakin 19y agoYou're welcome! Forgive me if this is obvious but there is one corner case worth mentioning with the Fu Cookie approach. The Fu Cookie authenticator expires. Be sure to consider what happens if this expiration happens in the middle of some complex user-operation. Ideally you will save the user's state, reauthenticate and then automatically resume the interrupted operation. It is possible to do this all using cookies or hidden form fields rather than maintaining a data-structure (or closure ;) ) on the server-side. If you do use cookies/form fields consider HMACing the operation-state data in the same manner that you HMAC the Fu Cookie authenticator.