Go ![]() | New ![]() | Find ![]() | Notify ![]() | Tools ![]() | Reply ![]() | |
Baroque Bloke![]() |
The challenge is a request to enter your username and password. No security issue with that challenge. The response to that challenge is certainly not presented "in the clear" – it’s encrypted. Am I misunderstanding your comment? Serious about crackers. | |||
|
| Member |
At work, we had a Secure Id token. A small device that used a rolling code much like a garage door opener | |||
|
| Optimistic Cynic |
Yes. I'm using the word "challenge" as a general term for credential presentation, not as a specific challenge/response mechanism. My comment was intended to illustrate that various authentication methods are not without their costs, closing a "hole" in one aspect often exposes an attack surface in another. Basically, if the entity you are authenticating against maintains their knowledge base (e.g. a list of valid passwords) in hashed or encrypted form, they must receive your credentials in plain text. Only if they maintain a plain text knowledge base can credentials be presented in encrypted or hashed formats. So somewhere there has to be plain text in the conversation or on a storage medium, which is open to interception by an out-of-bounds attack. | |||
|
| Member |
Just adding some clarity for the thread, not disagreeing. Credentials entered in the browser on a secure site are encrypted in transit as part of the browser session, but then would be decrypted at the other end. Thus, plain text presentation to the authentication layer. -- I always prefer reality when I can figure out what it is. JALLEN 10/18/18 https://sigforum.com/eve/forum...610094844#7610094844 | |||
|
| As Extraordinary as Everyone Else |
Do you use one you’d care to recommend? ------------------ Eddie Our Founding Fathers were men who understood that the right thing is not necessarily the written thing. -kkina | |||
|
Baroque Bloke![]() |
^^^^^ I use mSecure. $14.99/year. There are free apps for my MacBook and iPhone. Probably PC and Android too. I pay the annual fee via an Apple “subscription”. Very convenient. There’s a media choice for syncing the apps: Wi-Fi, Dropbox, and mSecure’s own server. I use the latter. No additional cost, and no third-party involved. I’ve never seen that server down. I’ve used mSecure for more than ten years. Serious about crackers. | |||
|
| Powered by Social Strata | Page 1 2 |
| Please Wait. Your request is being processed... |
|

