Secure Cookie Auth with CouchDB
jasondavies.com
jasondavies.com
But SRP is totally irrelevant in a browser context, because any technique you can use to safely deliver SRP code to the browser can be used just as easily to safely exchange passwords directly. SRP will be relevant when browsers bake it in.
> But SRP is totally irrelevant in a browser context, because any technique you can use to safely deliver SRP code to the browser can be used just as easily to safely exchange passwords directly. SRP will be relevant when browsers bake it in.
If you read the conclusion, this is why I ripped out the SRP stuff :-) Can't wait for TLS-SRP to hit the browsers.
But, all this article said is: "Hey we have a great Idea and it Works. [mumbles]For sufficiently small values of works."