vikrr

10 pts ยท March 6, 2017


What a cham-pion!

8 years ago | Likes 1 Dislikes 0

Yea, just don't do that anywhere near any sensitive data.

8 years ago | Likes 2 Dislikes 0

5678

8 years ago | Likes 1 Dislikes 1

Now you're using unique salts which makes it harder... an attacker still can focus on one specific account - it's not that long.

8 years ago | Likes 1 Dislikes 0

Not outdated per se, just easy to crack by today's standards.

8 years ago | Likes 1 Dislikes 0

There is no encryption there?

8 years ago | Likes 1 Dislikes 0

Please at least use bCrypt.

8 years ago | Likes 1 Dislikes 0

Rest in peace.

8 years ago | Likes 2 Dislikes 0

Can I have one?

8 years ago | Likes 1 Dislikes 0

456

8 years ago | Likes 1 Dislikes 0

Bro

8 years ago | Likes 1 Dislikes 0

Neato

8 years ago | Likes 2 Dislikes 0

10

8 years ago | Likes 2 Dislikes 1

Interesting

8 years ago | Likes 1 Dislikes 0

Interesting

8 years ago | Likes 1 Dislikes 0

Yes, there are some .htaccess directives for that. (Authtype, AuthName, AuthUserFile and probably others I forgot about)

8 years ago | Likes 1 Dislikes 0

https://stripe.ian.sh

8 years ago | Likes 1 Dislikes 0

OP means specifically a green bar with a Subject name, but even that can be faked with enough means.

8 years ago | Likes 4 Dislikes 0

understand and pop a password input. But the password can be omitted in the URI. 2/2

8 years ago | Likes 2 Dislikes 0

Yes. If the server doesn't accept it, it can return a 401 Unauthorized with a coherent WWW-Authenticate header, which your browser will 1/2

8 years ago | Likes 2 Dislikes 0

.

8 years ago | Likes 2 Dislikes 0