Path: csiph.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: Stefan+Usenet@Froehlich.Priv.at (Stefan Froehlich) Newsgroups: comp.lang.php Subject: Re: HTTPS data in a form Date: 20 Sep 2016 21:04:35 GMT Lines: 28 Message-ID: References: <52647a62-05fe-ade7-9de8-e434f646aad9@arnowelzel.de> <2368565.mvXUDI8C0e@PointedEars.de> <0538bd0a-15af-6afe-260c-38fb970c56d9@arnowelzel.de> <3934285.LvFx2qVVIh@PointedEars.de> <9003351.nUPlyArG6x@PointedEars.de> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Trace: individual.net 3p3v43us/BkJf2RbcgKa3QUCJkmA5XIec/f0w8M35SSeX39KQ= X-Orig-Path: not-for-mail Cancel-Lock: sha1:0ZY35dpIWCzgsI50jvJ9t8oeBPg= X-Blattlinie: dieser Artikel repraesentiert meine persoenliche Meinung X-Medieninhaber: Stefan Froehlich X-Verleger: Stefan Froehlich X-Verlagsort: Wien User-Agent: tin/2.2.1-20140504 ("Tober an Righ") (UNIX) (Linux/3.16.0-4-amd64 (x86_64)) Xref: csiph.com comp.lang.php:17082 On Tue, 20 Sep 2016 15:40:04 Thomas 'PointedEars' Lahn wrote: > Stefan Froehlich wrote: > > On Mon, 19 Sep 2016 23:28:27 Thomas 'PointedEars' Lahn wrote: > >> because the used encryption/hashing algorithm would have to reside > >> on the client in the form of a client-side script *for every > >> attacker plain to see* (obfuscation is _not_ protection). > > If you use asymmetric encryption this would not be the big problem. > Exposing the used encryption algorithm to a potential attacker is a security > leak. No. Security by obscurity. > It is a big problem in any case. The problem in this case is somewhere else (as you and others did point out already) Bye, Stefan -- http://kontaktinser.at/ - die kostenlose Kontaktboerse fuer Oesterreich Offizieller Erstbesucher(TM) von mmeike Stefan - Wer trägt heute schon Eulen nach Athen? (Sloganizer)