LWN.net Logo

Presumably secret is constant per-server

Presumably secret is constant per-server

Posted May 8, 2008 9:39 UTC (Thu) by tialaramex (subscriber, #21167)
In reply to: Cryptographic splicing makes for a Wordpress vulnerability by eru
Parent article: Cryptographic splicing makes for a Wordpress vulnerability

The secret is presumably constant, per server. So you need to get the server to work out a
hash for you, with the same content as the one it would issue to a real administrator.
Fortunately their idiotic design† makes exactly this possible.

† I'd love to be charitable, but the thing about cryptography is that you can't be trusted to
DIY. If you're not using a system designed by someone who knew what they were doing and then
reviewed by others with an interest in revealing any defects, then you might as well go back
to storing plaintext passwords or using the honour system. Really.


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds