[security] Passwords in the clear

Claus Färber GMANE at faerber.muc.de
Fri Feb 9 08:24:00 UTC 2007


Recordon, David <drecordon at verisign.com> schrieb/wrote:
> +1, any OP worth its code will use HTTPS when working with passwords or user data.

That does not help if a rouge RP sends the user elsewhere and the MITM  
provides a valid SSL certificate for his "lookalike" domain name.

Claus





More information about the security mailing list