Re: SSL Encryption

From: Herb Martin (news_at_LearnQuick.com)
Date: 07/16/03


Date: Wed, 16 Jul 2003 09:37:48 -0500


SSL itself is encrypted so as long as you stay in the HTTPS
protocol you have encryption for any data INCLUDING
passwords.

This is why BasicAuthentication WITH SSL is pratically an
extra IIS authentication method that make the insecure Basic
(clear text) effectively an encrypted authentication -- and
open standard, pretty much browser version independent.

(Since version 2.0 of the major browsers and even Lynx
has an SSL verion.)

"William" <wchristian@smithcom911.com> wrote in message
news:004501c34ba5$a9eacbd0$a101280a@phx.gbl...
> When you attempt to connect to OWA over https://, does it
> start encrypting immediately or does it wait until you
> have authenticated with your network username and
> password, and then encrypt everything after that?
> I know this seems like a dumb question, but I just want
> to be 100% sure that our login names and passwords are
> not exposed when using OWA.
>
> Thanks,



Relevant Pages

  • Re: Secure web authentication system w/o SSL and PKI
    ... Authentication has nothing to do with SSL. ... Why do you want symmetric encryption? ...
    (comp.security.misc)
  • Re: [fw-wiz] Exposed serial connection
    ... Authentication and encryption can be done using ssh. ... both ssh and ssl have had security issues lately. ... I have no financial interest in Cyclades, ...
    (Firewall-Wizards)
  • .htaccess authentication control via PHP
    ... authentication is pretty much the only way forward. ... The problem arises with the password encryption. ... the passwords are encrypted before they're stored in the ... via the PHP script, it doesn't encrypt the passwords in the same way. ...
    (comp.lang.php)
  • Re: one way permutation?
    ... It's still modular encryption, but it's only ... For that, you DO need public-key techniques, such as ... Look on my page about "Passwords and ... kind -> owner ...
    (sci.crypt)
  • Obfuscating sensitive data? (was: response to tax software not encrypting tax info)
    ... Encryption without a key is useless. ... If you can retrieve the file, brute force is always possible, so nothing ... attacker laugh, assuming he is just a bit smarter than a piece of wood. ... Never just obfuscate the passwords by using a generic key. ...
    (Bugtraq)

Quantcast