LWN.net Logo

Cryptographic splicing makes for a Wordpress vulnerability

Cryptographic splicing makes for a Wordpress vulnerability

Posted May 8, 2008 16:04 UTC (Thu) by TRS-80 (subscriber, #1804)
In reply to: Cryptographic splicing makes for a Wordpress vulnerability by epa
Parent article: Cryptographic splicing makes for a Wordpress vulnerability

REST based authentication is a in-depth study on how to make HTTP authentication more friendly, in part by using AJAX to log in via a normal HTML form and various apache config tricks. But really W3C should fix HTTP authentication so there's no need to use these sorts of egregious hacks - for example, you have to implement challenge-response yourself in JavaScript and phishing becomes a problem.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds