2 ms·
SSL is relevant and in my actual implementation, which I am prepping now, I do use SSL on the login form, but technically, the form it is submitting to needs to
by hayroob 17y ago
SSL is relevant and in my actual implementation, which I am prepping now, I do use SSL on the login form, but technically, the form it is submitting to needs to be SSL, but the form itself does not.
Since I wrote the article I have made some small adjustments to the AES key dialogue, they key is generated at the login form using javascript then sent as an ssl cookie to the authentication form and also stored into a local persistent storage, which is not accessible (barring an exploit.) Once the auth page is reached the aes and guid cookies are cleared. I suppose that a script could be crafted to cause the user to reveal the key and guid stored in persistent storage, this is something I am still working on securing against.
I will consider your suggestions carefully and attempt to integrate them as I work to code this out.
I have posted this discussion into the comments in the article and will be updating it tonight to reflect this conversation. Thank You.
- there 17y agothe form it is submitting to needs to be SSL, but the form itself does not then how do you guarantee the form is going to submit to an SSL-protected resource? the form and all of your javascript has to be sent over SSL, otherwise any of it can be tampered with to simply bypass your logic and post the form contents to an unencrypted resource. if you haven't already seen it, watch moxie's blackhat presentation about ssl: https://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Marlinspike https://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.htm...
- hayroob 17y agoThat seems like viable thought. I will watch the presentation when I get a chance, but for now I will modify the article to consider this scenario and my code already forces SSL on the login page and the authentication script.
- eli 17y agoYou're right -- but do you expect users to View Source to confirm its posting to an SSL url? How else would they be able to tell if a MITM altered the form to post somewhere insecure?
- jerf 17y agoWhat problem exactly are you trying to solve? Do you have an actual site in hand that you can't afford to run SSL on, but also can't afford to toss a couple of CPUs at? That's an awfully narrow window given how cheap CPU is now, and it's only getting narrower. Add to that the intrinsic diceyness of trying to build your own cryptographic system and it sure seems unlikely this is a win of any kind.