Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I was actually thinking that the client would store the private key somewhere (e.g. in an HTML5 browser:)) but what you described is brilliant and definitely works.

Something like that is not used probably because the bigger problem is clients getting hijacked, not servers.



Right, and when servers do get hijacked it tends to be a quick in and out, so compromises based on transient connections aren't much of a concern. Sending passwords over SSL with a good password hash on the other end solves everything if you assume that the attackers won't stick around listening on incoming connections.

Now I really want to implement my scheme using JavaScript crypto. If only I had a web site that needed secure logins.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: