Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6222373
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 24, 20262026-05-24T08:18:09+00:00 2026-05-24T08:18:09+00:00

Right now our application is designed to facilitate all communication via websockets after the

  • 0

Right now our application is designed to facilitate all communication via websockets after the initial load.

We are trying to figure out a solution to safely pass sensitive data via this transport.

So far we are thinking about a few things:

  1. Authentication of the websocket transport by passing back a unique
    hash stored in a session cookie delivered via SSL on initial load.
  2. Client-side encryption using something like a javascript bcrypt
    implementation to encrypt everything before it is transported.

  3. Just passing all sensitive data with a normal post via SSL even
    though we dont want to.

Something like number 1 would be the best outcome but we are unaware if websokets are vulnerable to things like man in the middle attacks even after authentication.

Any help sussing out possible security downfalls, or any other ideas on how to achieve true security over websockets would be greatly appreciated!

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-24T08:18:11+00:00Added an answer on May 24, 2026 at 8:18 am

    Connecting to a wss:// WebSocket URL rather than ws:// will use the browser’s standard TLS/SSL encryption to connect to the server. It’s equivalent to HTTPS vs HTTP. If you trust your browser’s SSL/TLS implementation then you can trust WebSocket wss:// connections since they use the same engine. You will need to have a signed SSL certificate configured with your websocket server, but that’s pretty much required anyways.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Right now I am trying to apply the n-tier architecture to our web application,
Right now we have AD/Exchange to manage all of our users logins/e-mail on-site at
I want to integrate a report writer in our web application. Right now ,
We currently have a Web Forms application deployed on IIS. Our goal right now
i am trying to implement dependency injection for our custom ModelBinders. Right now i
I'm working with an application right now for our project in school. My application
Right now the application being built by our team uses the built in MVC
Our applications use lot of custom built and third party libraries and right now
We have a script right now which our Windows users run on a Linux
For our site, Im using a lot of jQuery - right now Im looking

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.