Taiche (╯°□°)╯︵ ┻━┻ | ratibus a écrit :
Seul le marchand connait le prix de ses produits.
La banque (et son sytème de paiement) n'ont pas accès à cette base de données => pas de requete SQL.
Si le marchand propose au client de saisir ses infos bancaires sur son site (et d'appeler la banque en interface directe et donc de manière transparente pour le client), alors bien sûr il faut faire comme ça
|
OK, effectivement, s'il faut contacter le site de la banque, il faut passer le montant. Maintenant, est-ce que c'est la meilleure méthode, j'en sais rien, mais je comprends mieux.
ratibus a écrit :
Un excellent article : http://www.schneier.com/blog/archi [...] sis_o.html
Citation :
One-way hash functions are supposed to have two properties. One, they're one way. This means that it is easy to take a message and compute the hash value, but it's impossible to take a hash value and recreate the original message. (By "impossible" I mean "can't be done in any reasonable amount of time." ) Two, they're collision free. This means that it is impossible to find two messages that hash to the same hash value.
|
|
Une autre citation sur la même page :
Citation :
But there's an old saying inside the NSA: "Attacks always get better; they never get worse." Just as this week's attack builds on other papers describing attacks against simplified versions of SHA-1, SHA-0, MD4, and MD5, other researchers will build on this result. The attack against SHA-1 will continue to improve, as others read about it and develop faster tricks, optimizations, etc. And Moore's Law will continue to march forward, making even the existing attack faster and more affordable.
|
La conclusion étant :
Citation :
The Chinese cryptographers deserve a lot of credit for their work, and we need to get to work replacing SHA.
|
Donc oui, aujourd'hui c'est pas pratiquable sur le PC de tout un chacun. Mais dans quelques années, il est fort probable que si. ---------------
Everyone thinks of changing the world, but no one thinks of changing himself | It is the peculiar quality of a fool to perceive the faults of others and to forget his own | Early clumsiness is not a verdict, it’s an essential ingredient.
|