Path: csiph.com!2.us.feeder.erje.net!feeder.erje.net!1.eu.feeder.erje.net!weretis.net!feeder4.news.weretis.net!feeder1.news.weretis.net!news.solani.org!.POSTED!not-for-mail From: Thomas 'PointedEars' Lahn Newsgroups: comp.lang.php Subject: Re: HTTPS data in a form Date: Mon, 19 Sep 2016 23:36:01 +0200 Organization: PointedEars Software (PES) Lines: 26 Message-ID: <2008259.ElGaqSPkdT@PointedEars.de> References: Reply-To: Thomas 'PointedEars' Lahn Mime-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 8Bit X-Trace: solani.org 1474320962 10344 eJwFwQkBgAAIA8BK45c4gK5/BO/CUvLKM9KDwTmpM9nAcaAOzMF2RIrvB2vWg4zV63bl/h7dEQ4= (19 Sep 2016 21:36:02 GMT) X-Complaints-To: abuse@news.solani.org NNTP-Posting-Date: Mon, 19 Sep 2016 21:36:02 +0000 (UTC) User-Agent: KNode/4.14.2 X-NNTP-Posting-Host: eJwFwQEBwCAMAzBLHdCyy+Fj9S+BhFOh2kvUomkUZogZyIsm/24PmFe46WF9vWMcsE6Q9gMOwRD3 Cancel-Lock: sha1:TQ9b4UCaW5kxUM62kBe0RCye258= X-User-ID: eJwNysEBwEAEBMCWcCGnHJbtv4Rk3uMnNPA+4fE4nThgzKonT+SgAnYbKys6xjUIRqxvBqa8gSz+PwmWoj+NTBfF Xref: csiph.com comp.lang.php:17070 Richard Damon wrote: > If you don't want to use HTTPS, but normal HTTP, then as others have > said, you would need some client side code, likely javascript, to > encrypt the field before being sent. One warning, unless you are REAL > careful in how you do this, it may just add a false sense of security, They are *definitely* “[adding] a false sense of security” if they do this. > as you are still totally susceptible to man-in-the-middle attacks If they do this, MITM attacks are the least of their problems. *Everybody* can brute-force their way in because they are literally *handed the keys*. > and unless you are really careful to salt the login page, and make sure ^^^^^^^^^^^^^^^^^^^ > the salt matches, someone eves dropping can still just return the same > encrypted password to get access. ROTFL. You have no clue what you are talking about. -- PointedEars Zend Certified PHP Engineer | Twitter: @PointedEars2 Please do not cc me. / Bitte keine Kopien per E-Mail.