To LUGNET HomepageTo LUGNET News HomepageTo LUGNET Guide Homepage
 Help on Searching
 
Post new message to lugnet.admin.generalOpen lugnet.admin.general in your NNTP NewsreaderTo LUGNET News Traffic PageSign In (Members)
 Administrative / General / 6387
6386  |  6388
Subject: 
Re: PW validation (was: Re: Opinions wanted: article rating harmful?)
Newsgroups: 
lugnet.admin.general
Date: 
Sat, 22 Apr 2000 16:22:41 GMT
Viewed: 
2894 times
  
In lugnet.admin.general, Todd Lehman writes:
In lugnet.admin.general, Richard Franks writes:
Even if you have great passwords - can't just anyone in the intervening
networks between the user and LUGNET just snoop in and copy down the
unencrypted password?
As long as it's using http and not https, yes.  Once it's in a cookie, it's
no longer plaintext, so it's less susceptible to snooping although still
susceptible to playback attacks.

Aren't the contents of a cookie simply Base64-encoded?  I mean, it's a
wel-known and reversable format.

Cheers,
- jsproat



Message has 2 Replies:
  Re: PW validation (was: Re: Opinions wanted: article rating harmful?)
 
(...) I assume it's a one-way hash of some sort. I'd guess (without looking) that it's probably md5.... (25 years ago, 22-Apr-00, to lugnet.admin.general)
  Re: PW validation (was: Re: Opinions wanted: article rating harmful?)
 
(...) No, the last phase of encoding (and thus the first phase of decoding) for the sign-in cookie is a Base16 (ASCII hex [0-9A-F]) pass. This, however, is applied to an already-encrypted id/pw combo, which has been passed through a pad-style (...) (25 years ago, 22-Apr-00, to lugnet.admin.general)

Message is in Reply To:
  Re: PW validation (was: Re: Opinions wanted: article rating harmful?)
 
(...) As long as it's using http and not https, yes. Once it's in a cookie, it's no longer plaintext, so it's less susceptible to snooping although still susceptible to playback attacks. --Todd (25 years ago, 22-Apr-00, to lugnet.admin.general)

309 Messages in This Thread:
(Inline display suppressed due to large size. Click Dots below to view.)
Entire Thread on One Page:
Nested:  All | Brief | Compact | Dots
Linear:  All | Brief | Compact

This Message and its Replies on One Page:
Nested:  All | Brief | Compact | Dots
Linear:  All | Brief | Compact
    

Custom Search

©2005 LUGNET. All rights reserved. - hosted by steinbruch.info GbR