Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #17079

Re: HTTPS data in a form

From "J.O. Aho" <user@example.net>
Newsgroups comp.lang.php
Subject Re: HTTPS data in a form
Date 2016-09-20 18:39 +0200
Message-ID <e4d71qFseodU1@mid.individual.net> (permalink)
References (2 earlier) <2368565.mvXUDI8C0e@PointedEars.de> <0538bd0a-15af-6afe-260c-38fb970c56d9@arnowelzel.de> <3934285.LvFx2qVVIh@PointedEars.de> <e4c1iaFj9ncU1@mid.individual.net> <9003351.nUPlyArG6x@PointedEars.de>

Show all headers | View raw


On 09/20/2016 03:40 PM, Thomas 'PointedEars' Lahn wrote:
> Stefan Froehlich wrote:
> 
>> On Mon, 19 Sep 2016 23:28:27 Thomas 'PointedEars' Lahn wrote:
>>> because the used encryption/hashing algorithm would have to reside
>>> on the client in the form of a client-side script *for every
>>> attacker plain to see* (obfuscation is _not_ protection).
>>
>> If you use asymmetric encryption this would not be the big problem.
> 
> Exposing the used encryption algorithm to a potential attacker is a security 
> leak.  It is a big problem in any case.

Not at all, just see how PGP works, you send you public key to people,
they encrypt the e-mail and send it to you, you can decrypt it with your
private key. Even if they have your public key, they will not be able to
generate your private key not use the public key to decrypt any messages
encrypted with it.

Most encryption is done with "exposed" algorithms, for example openssl
source code is free for grabs and most algorithms are anyway publicly
documented, so you will be able to build your own encryption/decryption
functionality.
No difference if you do it in javascript, c++, c# or your own created
language, seeing the code will not make people just able to decrypt
things, unless it's rot_13.


-- 

 //Aho

Back to comp.lang.php | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

HTTPS data in a form bit-naughty@hotmail.com - 2016-09-15 21:45 -0700
  Re: HTTPS data in a form "J.O. Aho" <user@example.net> - 2016-09-16 07:52 +0200
  Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-17 15:57 +0200
    Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-17 21:17 +0200
      Re: HTTPS data in a form Jerry Stuckle <jstucklex@attglobal.net> - 2016-09-17 17:02 -0400
        Re: HTTPS data in a form "Peter H. Coffin" <hellsop@ninehells.com> - 2016-09-21 11:33 -0500
          Re: HTTPS data in a form Jerry Stuckle <jstucklex@attglobal.net> - 2016-09-23 08:47 -0400
          Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-24 22:11 +0200
      Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-19 21:36 +0200
        Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-19 23:28 +0200
          Re: HTTPS data in a form "Christoph M. Becker" <cmbecker69@arcor.de> - 2016-09-19 23:44 +0200
            Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-19 23:57 +0200
              Re: HTTPS data in a form "Christoph M. Becker" <cmbecker69@arcor.de> - 2016-09-20 19:00 +0200
          Re: HTTPS data in a form Jerry Stuckle <jstucklex@attglobal.net> - 2016-09-19 21:00 -0400
          Re: HTTPS data in a form Stefan+Usenet@Froehlich.Priv.at (Stefan Froehlich) - 2016-09-20 05:59 +0000
            Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-20 15:40 +0200
              Re: HTTPS data in a form "J.O. Aho" <user@example.net> - 2016-09-20 18:39 +0200
                Re: HTTPS data in a form Jerry Stuckle <jstucklex@attglobal.net> - 2016-09-20 14:36 -0400
              Re: HTTPS data in a form Stefan+Usenet@Froehlich.Priv.at (Stefan Froehlich) - 2016-09-20 21:04 +0000
                Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-24 21:58 +0200
                Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-26 19:43 +0200
              Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-23 09:14 +0200
                Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-24 22:00 +0200
                Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-26 19:44 +0200
          Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-20 08:20 +0200
            Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-20 15:41 +0200
              Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-23 09:02 +0200
                Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-24 22:06 +0200
                Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-26 19:49 +0200
  Re: HTTPS data in a form Richard Damon <Richard@Damon-Family.org> - 2016-09-18 14:22 -0400
    Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-19 23:36 +0200
      Re: HTTPS data in a form Jerry Stuckle <jstucklex@attglobal.net> - 2016-09-19 21:03 -0400
  Re: HTTPS data in a form "Peter H. Coffin" <hellsop@ninehells.com> - 2016-09-21 11:29 -0500

csiph-web