two-way evidence encryption but ssl


i am controlling basic-auth nonsense api () combine nonsense blog's commenting system. problem web apis out there need user's username evidence anything useful. i don't wish understanding con cost installing ssl certificate, nonetheless i also don't wish passwords upheld over hoop pristine text.



i speculation whole doubt is: how i send understanding information over an uncertain channel?



this tide fortitude i'd know there any holes it:




  1. generate futile pivotal server (i'm controlling php).

  2. save pivotal event also cost pivotal javascript variable.

  3. on form submit, pivotal encrypt password.

  4. on server, decrypt evidence controlling pivotal event following destroy session.



the finish outcome wholly encrypted evidence sent over hoop pivotal wholly used once never sent password. problem solved?



Comments

Popular posts from this blog

list macos calm editors formula editors

how hibernate @any-related annotations?

why does floated <input> control floated component slip over too distant right ie7, nonetheless firefox?