|
Posted by David T. Ashley on 01/10/07 05:28
"Gordon Burditt" <gordonb.olgg8@burditt.org> wrote in message
news:12q8o836pfg0i34@corp.supernews.com...
> >Now, as far as the technical matters ...
>>
>>The scheme you've presented goes against known best practices.
>
> Known best practices include:
> Don't store the passwords in plain text or reversible encryption.
> Don't transmit passwords in the clear over the network.
>
> Unfortunately, with many protocols, you can't have both.
> Challenge-response protocols may require that you have the actual
> password, not a hash of it, on both sides to perform the
> challenge-response.
You've gone mad. Cite an example where this is the case.
Navigation:
[Reply to this message]
|