Re: Forms and integrated authentication combined
From: John Saunders (john.saunders)
Date: 03/09/04
- Next message: Jeffrey H: "Tracing in ASP.NET"
- Previous message: Joe: "Test how displayed on a mac"
- In reply to: Jason: "Forms and integrated authentication combined"
- Messages sorted by: [ date ] [ thread ]
Date: Tue, 9 Mar 2004 18:57:56 -0500
"Jason" <jason@solid.freeserve.co.uk> wrote in message
news:c2ljd4$8pj$1@news5.svr.pol.co.uk...
...
> Forms authentication suffers from the problem that users will inevitably
use
> the same password as their NT account, meaning passwords would be stored
in
> a less secure database. I could authenticate on the domain each time they
> log in, but then the login.aspx page could be hacked to siphon off these
> passwords.
I don't get it. How would authenticating against the domain turn login.aspx
into a source of passwords?
-- John Saunders John.Saunders at SurfControl.com
- Next message: Jeffrey H: "Tracing in ASP.NET"
- Previous message: Joe: "Test how displayed on a mac"
- In reply to: Jason: "Forms and integrated authentication combined"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|