![]() |
SSL Login
Would it be possible to implement a secure SSL login for the forums, or even better a site wide implementation?
Even a self-signed certificate would be great; I don't like passing my login credentials over the air in plain-text (I know they are md5 hashed but they can be fairly trivial to decrypt). |
Re: SSL Login
Quote:
[added] You are right, it is md5 before it sends to server. |
Re: SSL Login
Quote:
Edit: Just saw your edit. Suppose hashing with salt is good enough, still it's rather easy to hijack the session. |
Re: SSL Login
Quote:
Quote:
|
Re: SSL Login
Quote:
Having said that, if a plain, unsalted md5 sum is accepted by the server, then for all intents and purposed the md5 is a plaintext password. An eavesdropper doesn't have to crack it, they can just send it as-is to authenticate. |
Re: SSL Login
Is there no demand for this?
If not I'll let the thread rest until someone else feels the need to bump it. |
All times are GMT. The time now is 13:04. |
vBulletin® Version 3.8.8