I tried logging in on browser and I had inspected the request. My password was sent in plaintext. Is this a infosec.pub issue or a Lemmy one?

you are viewing a single comment's thread
view the rest of the comments
[–] [S] 1 point 3 years ago (1 child)

First of all thanks for the very detailed response. I have a few questions.

  1. Like you said, why not use public key cryptography? Why is it not well supported for web-apps?

  2. Why not use something like Diffie-Hellman algorithm to share the password? Signal protocol uses ECDHE so I am assuming that it's safe against mitm which the base Diffie-Hellman is vulnerable to (I might be wrong. I couldn't find if it waa vulnerable or not).

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 3 years ago (1 child)

    You are describing TLS, which is commonly used for websites and web apps.

    Try the following command:

    openssl s_client -connect infosec.pub:443
    

    The public key, the authority that signed the certificate, and the cypher used will all be visible.

    For me, the cipher used is ECDHE-RSA-AES256-GCM-SHA384.

  • source
  • parent
  • hideshow 2 child comments