Win a copy of Java 9 Revealed this week in the Features new in Java 9 forum!
  • Post Reply Bookmark Topic Watch Topic
  • New Topic

Form and Basic Authentication  RSS feed

 
Yogesh Hingmire
Ranch Hand
Posts: 61
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Basic authentication i understand uses base64 encoding, but does form based authentication uses base64 encoding too ?

I believe form based authentication transmits username/pwd as plain text.

Thanks again
Yogesh
 
Ulf Dittmer
Rancher
Posts: 42970
73
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Yes, form-based auth is in clear text, because to the browser it's just a regular form submission - it has no idea that it's user credentials. Of course, a base64-encoded password is only marginally harder to recover than a plain text one.
 
  • Post Reply Bookmark Topic Watch Topic
  • New Topic
Boost this thread!