Dashboard > People > James Gardner > Home
  James Gardner Log In | Sign Up   View a printable version of the current page.  
  Home
Added by James Gardner, last edited by James Gardner on Apr 27, 2007  (view change)
Labels: 
(None)

I'm a web developer and co-founder of the Pylons project. I also wrote FormBuild, AuthKit and the Python Web Modules.

I'm a director of 3aims Ltd http://3aims.com and I've started a blog here: http://jimmyg.org

You can contact me at james at pythonweb dot org.

You've written the following in Chapter 19, one of the AuthKit chapters:
Even HTTP digest authentication which does use some encryption on the password isn't particularly secure because anyone monitoring the network traffic could simply send the encrypted digest and be able to sign onto the site themselves although they wouldn't be able to obtain the user's password so it is slightly better. Even if you are using digest authentication it is worth using SSL too.
You're sure HTTP Digests are susceptible to replay attacks? A simple MD5 hash of the password is, but a digest is much more than that, unless I've misread the spec. --me@lbruno.org

Posted by Anonymous at Feb 08, 2008 12:14 | Permalink | Reply To This
Site running on a free Atlassian Confluence Open Source Project License granted to Pylons. Evaluate Confluence today.
Powered by Atlassian Confluence, the Enterprise Wiki. (Version: 2.3.3 Build:#645 Feb 13, 2007) - Bug/feature request - Contact Administrators