Talk:Java Server Faces

Revision as of 12:30, 11 June 2007 by Ebing (Talk | contribs)

Jump to: navigation, search

EUxx discussion

I think the blog by EUxx missed some of the details of the implementation. Note that while the MAC and the IV are known, there is still a secret key known to the server used in the MAC that prevents the client from generating a new MAC. This is a fairly common pattern. You can see Inderjeet's response at:

I think we should either take this section out, or expand on why its an issue. Ebing 14:30, 11 June 2007 (EDT)