<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Password Encryption at Transport layer?? in ArcGIS Viewer for Flex Questions</title>
    <link>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414857#M11827</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Original User: GISDev01&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;BR /&gt;&lt;BR /&gt;you seeing same stuff on your end Dev01?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sure am, I just tested it this morning. I did a string search through all packets within a 30 second window of submitting the credentials and there is no match for my username or password anywhere to be found. I then isolated the SSL traffic and it matches the source and dest. IP and timestamp, so we do both have proof it is being encrypted.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;According to Squillman at Serverfault, "Yes, POST data should be encrypted. Everything in the HTTP request should be encrypted in an SSL conversation. Firebug gets its info after SSL data has been decrypted by the browser. "&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://serverfault.com/questions/106905/is-post-data-encrypted-over-an-ssl-connection"&gt;http://serverfault.com/questions/106905/is-post-data-encrypted-over-an-ssl-connection&lt;/A&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Jun 2013 11:28:12 GMT</pubDate>
    <dc:creator>Anonymous User</dc:creator>
    <dc:date>2013-06-07T11:28:12Z</dc:date>
    <item>
      <title>Password Encryption at Transport layer??</title>
      <link>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414851#M11821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;noticed that when using Fire Bug the 'Post Get token' to access secure map services show the user name and password as plane text. is this getting encrypted at the transport level?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[ATTACH=CONFIG]25096[/ATTACH]&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 19:57:17 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414851#M11821</guid>
      <dc:creator>DanielSmith</dc:creator>
      <dc:date>2013-06-06T19:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: Password Encryption at Transport layer??</title>
      <link>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414852#M11822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Original User: GISDev01&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;noticed that when using Fire Bug the 'Post Get token' to access secure map services show the user name and password as plane text. is this getting encrypted at the transport level?&lt;BR /&gt;&lt;BR /&gt;[ATTACH=CONFIG]25096[/ATTACH]&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Yes. Look into how "HTTPS" works. That S makes all the difference.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;However, Esri has a long way to go to providing Enterprise Level security in an out-of-the-box solution (not referring to this question in particular).&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 21:03:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414852#M11822</guid>
      <dc:creator>Anonymous User</dc:creator>
      <dc:date>2013-06-06T21:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Password Encryption at Transport layer??</title>
      <link>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414853#M11823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Indeed HTTPS. Just wanted to make sure that at the transport layer this was actually getting encrypted. Thnx for the assurance GISDev01. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ESRI folks care to comment on this?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 21:26:50 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414853#M11823</guid>
      <dc:creator>DanielSmith</dc:creator>
      <dc:date>2013-06-06T21:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: Password Encryption at Transport layer??</title>
      <link>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414854#M11824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Original User: GISDev01&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Indeed HTTPS. Just wanted to make sure that at the transport layer this was actually getting encrypted. Thnx for the assurance GISDev01. &lt;BR /&gt;&lt;BR /&gt;ESRI folks care to comment on this?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;If you want to see what is going over the wire, and as a fun research opportunity if you want to know more about Network Security, go ahead and install Wireshark and watch all of the traffic going over the wire and you will find your answer. I'm actually interested in what you find because I haven't looked at that traffic yet. I will check it later tonight myself.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 22:24:39 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414854#M11824</guid>
      <dc:creator>Anonymous User</dc:creator>
      <dc:date>2013-06-06T22:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Password Encryption at Transport layer??</title>
      <link>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414855#M11825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;If you want to see what is going over the wire, and as a fun research opportunity if you want to know more about Network Security, go ahead and install Wireshark and watch all of the traffic going over the wire and you will find your answer. I'm actually interested in what you find because I haven't looked at that traffic yet. I will check it later tonight myself.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Holy Jesus!!! are you reading my mind (or rather my traffic (: )?&amp;nbsp; totally digging into wireshark now. Will Let you know what i find.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 23:01:30 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414855#M11825</guid>
      <dc:creator>DanielSmith</dc:creator>
      <dc:date>2013-06-06T23:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Password Encryption at Transport layer??</title>
      <link>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414856#M11826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Original User: D.E.Smith99&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Holy Jesus!!! are you reading my mind (or rather my traffic (: )?&amp;nbsp; totally digging into wireshark now. Will Let you know what i find.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ok. here it is. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1) booted up wire shark&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2) opened browser and activated Fire Bug&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3) navigated to and logged into web app&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4) isolated the 'POST Generate Token' that was showing username and password as text in Fire Bug.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5) noted the time stamp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;6) back to wire shark&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;7) filtered by tcp.port ==443&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Identified two frames based on filtered port, source and destination IP addresses, time stamp, and payload&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;9) dug through the packets looking for username and password or other indications.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10) located the SSL branch in the tree and the encrypted application data&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;i am still looking through the wire shark documentation to fully understand the information and learn a thing or two. But the application data is encrypted no matter what Fire Bug is telling me. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;you seeing same stuff on your end Dev01?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jun 2013 00:50:45 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414856#M11826</guid>
      <dc:creator>Anonymous User</dc:creator>
      <dc:date>2013-06-07T00:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Password Encryption at Transport layer??</title>
      <link>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414857#M11827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Original User: GISDev01&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;BR /&gt;&lt;BR /&gt;you seeing same stuff on your end Dev01?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sure am, I just tested it this morning. I did a string search through all packets within a 30 second window of submitting the credentials and there is no match for my username or password anywhere to be found. I then isolated the SSL traffic and it matches the source and dest. IP and timestamp, so we do both have proof it is being encrypted.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;According to Squillman at Serverfault, "Yes, POST data should be encrypted. Everything in the HTTP request should be encrypted in an SSL conversation. Firebug gets its info after SSL data has been decrypted by the browser. "&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://serverfault.com/questions/106905/is-post-data-encrypted-over-an-ssl-connection"&gt;http://serverfault.com/questions/106905/is-post-data-encrypted-over-an-ssl-connection&lt;/A&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jun 2013 11:28:12 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-viewer-for-flex-questions/password-encryption-at-transport-layer/m-p/414857#M11827</guid>
      <dc:creator>Anonymous User</dc:creator>
      <dc:date>2013-06-07T11:28:12Z</dc:date>
    </item>
  </channel>
</rss>

