/    Sign up×
Community /Pin to ProfileBookmark

Secure login without paying for SSL certificates… Is it possible?

Hi all,

As the title says, I’m looking to see if I can figure out some sort of secure login without having to shell out cash for SSL certification. I did a cryptography class a while back for my masters and I remember there being quite a few things you could do to secure connections between a server and a client. Of course, don’t ask me now exactly what they were (out of sight, out of mind right?). But I’m going back and checking the little notes I had and so far have thought of a fairly simple system with an initial broadcast from the client just saying “hey, time for me to log on”, followed by transmission of a random string by the server and then a transmission of a hash of some sort of concatenation of the username, password and hash.

I’m sure this in itself is not really that secure. On top of that, if someone is in the middle of the transaction they can easily intercept the data and act as if they are the client.

Is there really no way to secure this transaction without a certificate?

Thanks for any info you can provide

to post a comment
PHP

0Be the first to comment 😎

×

Success!

Help @DJRobThaMan spread the word by sharing this article on Twitter...

Tweet This
Sign in
Forgot password?
Sign in with TwitchSign in with GithubCreate Account
about: ({
version: 0.1.9 BETA 6.3,
whats_new: community page,
up_next: more Davinci•003 tasks,
coming_soon: events calendar,
social: @webDeveloperHQ
});

legal: ({
terms: of use,
privacy: policy
});
changelog: (
version: 0.1.9,
notes: added community page

version: 0.1.8,
notes: added Davinci•003

version: 0.1.7,
notes: upvote answers to bounties

version: 0.1.6,
notes: article editor refresh
)...
recent_tips: (
tipper: @meenaratha,
tipped: article
amount: 1000 SATS,

tipper: @meenaratha,
tipped: article
amount: 1000 SATS,

tipper: @AriseFacilitySolutions09,
tipped: article
amount: 1000 SATS,
)...