3 ms·
While I agree with the sentiment in the Ars article, it seems to suggest that your password is submitted to a remote server. The check is completely client-side
by wmkn 13y ago
While I agree with the sentiment in the Ars article, it seems to suggest that your password is submitted to a remote server. The check is completely client-side though.
http://www.intel.com/content/dam/www/public/us/en/apps/password-security-toolkit/js/password.js http://www.intel.com/content/dam/www/public/us/en/apps/passw...
- thedufer 13y agoThat's not their point. An unsecured site can easily be spoofed; a secured one would require either getting intel's ssl cert or convincing users to click through a big "dont trust this site" page in their browser. The fact that they don't send the password just means that a MITM needs to put in slightly more work.
- tbrownaw 13y agoa secured one would require either getting intel's ssl cert or convincing users to click through a big "dont trust this site" page Or breaking into their DNS registrar and getting your own cert for their domain, or breaking into any one of the many many dozens of CAs that most browsers trust...
- thedufer 13y agoFair enough. Those are still generally on the order of very difficult, and certainly more difficult than doing none of those things at all.