Posted by Alexander Mueller on 01/11/08 00:52
Alexander Mueller wrote:
>
> Sorry, but what should be weak about this? You havent backed your
> statement with nothing. Please state facts and not only rumors.
In case you were referring to the potential problem that the password
database is being attacked, then yes, this is admittedly a weak point by
design and shared with the well known Digest Authentication. If you have
a suggestion or idea on how to solve it it would be most welcome however.
Except for this one point however, it still keeps the password itself
secret and prevents replay attacks as well.
Alexander
[Back to original message]
|