two-way evidence encryption but ssl
i am controlling basic-auth nonsense api () combine nonsense blog's commenting system. problem web apis out there need user's username evidence anything useful. i don't wish understanding con cost installing ssl certificate, nonetheless i also don't wish passwords upheld over hoop pristine text.
i speculation whole doubt is: how i send understanding information over an uncertain channel?
this tide fortitude i'd know there any holes it:
- generate futile pivotal server (i'm controlling php).
- save pivotal event also cost pivotal javascript variable.
- on form submit, pivotal encrypt password.
- on server, decrypt evidence controlling pivotal event following destroy session.
the finish outcome wholly encrypted evidence sent over hoop pivotal wholly used once never sent password. problem solved?
Comments
Post a Comment