Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 1087101
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 16, 20262026-05-16T22:53:46+00:00 2026-05-16T22:53:46+00:00

It has just occurred to me that when my Flex application does a ChannelSet.login,

  • 0

It has just occurred to me that when my Flex application does a ChannelSet.login, it is essentially sending the username and password over the wire in an unencrypted form to the BlazeDS server. While I use the binary AMF protocol over an AMFChannel, it would take nothing for somebody to sniff these passwords.

Most of my clients do not want to run their application on an https (SSL) protected site. So what is the best way to do this? I use Spring security on the backend to do authentication.

Should I encrypt the credentials myself before calling login? I guess then I would need to know the server-side encryption algorthym.

Thoughts?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-16T22:53:47+00:00Added an answer on May 16, 2026 at 10:53 pm

    Without SSL you can only resort to a shared encryption technique between client and server. In that case you can implement a custom LoginCommand in BlazeDS that will decrypt the incoming encrypted username/credentials for use on the server side.

    There are other techniques (SSO, PreAuthentication, SessionKeys) but if your clients wont shell out for SSL or be prepared to force their users to use a self signed Selg Signed SSL certificate, then i doubt they will go for the alternatives.

    If you are that worried about the username/password being comprpmised, then the minimum requirement is SSL when using ChannelSet.login with username/password.

    A good solution in my humble opinion is a login via HTTPS with username/password, which the issues a session key, you can then use the username/sessionkey over HTTP to check that an oncoming non-secure request is from an authemticated user. The sessionkeys timeout after an arbitrary amount of time.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Using Visual Studio 2005, the debugger tells me that a deadlock has occurred just
Our team has just started developing for the Sitecore CMS. We find that after
Since the time has just changed the past weekend in places that use Daylight
I've always just used OpenOffice Draw and it just occurred to me that there
Our WCF service has just one method: [ServiceContract(Name = Service, Namespace = http://myservice/)] [ServiceKnownType(GetServiceKnownTypes,
my co-worker has just create a new branch in the git repository which we
my certificate has just expired. I renewed it on Team section, then renew provisioning
A new colleague has just suggested using named HQL queries in Hibernate with annotations
i just wanted to put a selection on my picturebox.image but this has just
I have an XPage which has just broken due to (what should have been)

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.