2 ms·
It requires the server to store _either_ the password or the hash of the concatenated username, password, and realm. As long as the realm used in the challenge
by mastrix 17y ago
It requires the server to store _either_ the password or the hash of the concatenated username, password, and realm. As long as the realm used in the challenge is consistent, the password need not be stored (at all, anywhere).
- tptacek 17y agoIf you want the challenge to be password-equivalent, then yes, you can avoid storing the password. This defeats one of the purposes of digest authentication. Note also that by doing this, you're also conceding to store the password in an extremely insecure hashed format. It's not as bad as cleartext, but it's markedly worse than a real password hash.