Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Encryption generally doesn’t provide authentication, so I wouldn’t be surprised if that Apache module allows a user to flip is_admin=0 to 1 because the encryption is sufficiently malleable to do that. Especially because that page mentions 3DES.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: