Re: MD5 Collisions and Cached Authentcation

2014-08-01 Thread Ben Reser
On 7/31/14 2:27 PM, Ben Reser wrote: > On 6/5/14 11:29 PM, Ben Reser wrote: >> On 6/5/14, 6:16 PM, Bert Huijben wrote: >>> Do we make sure that we only send the password to an exact match of the >>> realm? >>> Otherwise somebody might be able to theoretically steal passwords by using a >>> special

Re: MD5 Collisions and Cached Authentcation

2014-07-31 Thread Ben Reser
On 6/5/14 11:29 PM, Ben Reser wrote: > On 6/5/14, 6:16 PM, Bert Huijben wrote: >> Do we make sure that we only send the password to an exact match of the >> realm? >> Otherwise somebody might be able to theoretically steal passwords by using a >> special realm string on a completely different serv