Thursday, August 11, 2005

And all I had to all this time was ask...

Apparently Blogger does support SSL login. I didn't find a link to it anywhere, but if you just add the 's' to the URL you get the happy yellow lock thing in your browser. It's a useful bookmark to have if you don't like your password being sent all around the internet and back in plain-text1. 1. I recently found out that some websites that don't use SSL don't actually send your password in the clear. They use javascript to compute a hash of your password, and that's what they send. I like this trick. It's clever. I never thought of using javascript to compute the hash of the password before it is sent, rather than at the server, as it is usually done. So your account for that particular site can still be hacked using just a plain old packet-sniffer, but your actual password won't be compromised, which is a good thing if you happen to use the same password for your online banking or somesuch thing.

0 Comments:

Post a Comment

<< Home