(03-19-2015, 07:15 AM)Brawler Wrote: I am referring to the hashing itself... It's not something that is typically done on the client's machine. And I was eluding to the idea that a seasoned developer would not do something like that unless he had a good reason.... However, a noob might do something like that because he didn't know any better.
But the thing is, a well seasoned developer WOULD do something like this, as it's actually more secure than sending user login information in plain text. I get frustrated because I keep repeating this but you still refuse to admit your wrong:
(03-19-2015, 01:04 AM)Dyme Wrote: If anything it's better than sending the password in plain text as anyone trying to preform a MITM attack will only see the hashed pass.
It's also worth noting that if you took three seconds to actually read the code, you could see that this is actually the login form used for
TYPO3, an extremely popular CMS with over 8 million downloads:
Code:
<!-- TYPO3 Script ID: typo3/index.php -->
<title>TYPO3 Login: qeep</title>
<meta name="generator" content="TYPO3 4.5, http://typo3.com/, © Kasper Skårhøj 1998-2009, extensions are copyright of their respective owners." />
So no, this isn't a "noob" programmer who probably has other flaws in his code. This is a team of professionals who run and maintain one of the largest CMSs used on the net today. Your whole point in invalid.
(03-19-2015, 07:15 AM)Brawler Wrote: However, you can't prove that it ISN'T the password that is being stored in the database anymore then I can prove it is.
But why does this "proof" even matter what so ever? The only time the user supplied password will equal the one stored in the DB is if the user logging in knows it... otherwise passwords supplied by attackers (which is what we're discussing) will NOT equal the one stored in the db, as they simply don't know it. I don't understand what you're trying to get at here.
(03-19-2015, 07:15 AM)Brawler Wrote: True... However you said "throttling the backend".
I wouldn't interpret this as the same thing.
No, I did not say that. Why quote me wrongly when you could have just went back a page? Oh, because it's clear that I didn't say that and you're trying to warp my words to make yourself seem correct.
(03-19-2015, 01:04 AM)Dyme Wrote: simply implement some sort of login throttling in your backend
I never said to throttle the backend, I said to throttle logins IN your backend (which is PHP). Just admit you misread my reply and get over it.
(03-19-2015, 07:15 AM)Brawler Wrote: I'm trying really hard not to let this turn into some "Who has the bigger dick"/"Internet tough-guy" forum bullshit, but your not making it easy for me.
If you spent a bit less time trying to "big internet tough-guy"
Yeah and you're not doing the same thing you're accusing me of doing here, right? I responded to you in that manner because I get frustrated when I have to correct people over and over again yet they still insist they're right... and I hate to say it to you, but you're not right here.
Ending this convo now as if you still decide to disagree with me it's clear you're just doing so for the sake of arguing. Feel free to respond and make yourself look like an even bigger moron, though.