-2

Possible Duplicate:
Client side password hashing

How one design support for digest authentication in client side. HTML form probably won't help. Does one need javascript and set the header explicitly or any better way.

bsr
  • 121
  • 3

1 Answers1

2

You don't because its an OWASP Violation. You have to use HTTPS, for logging in AND the lifetime of the session.

rook
  • 47,004
  • 10
  • 94
  • 182
  • Thank you for that resource. I am surprised it is considered the duplicate of the mentioned qn as that was related to why client side hashing. anyway, doesn't matter, this was my first qn :-(. While reading about security, I had the impression that Digest based auth is in lieu of basic-http auth. Anyway thanks for the link. – bsr Nov 03 '12 at 12:33