Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Hash based challenge-response authentication does require the server to know the plain password.

Not true. Read up on HTTP Digest authentication. It's described in RFC2617.



Oh please. That's 12 years old, it can't possible still apply.

</troll>




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: