From: Stevie O
Subject: Security
Date: Sun, 16 Sep 2001 19:39:56 -0400

Has anyone considered having a challenge-response type authentication, where the servers ends a challenge string, and the client returns a response?

Two examples I can think of:
(1) LANMAN/NetBIOS: Challenge string is DES encrypted with the user's password.
(2) MSN Messenger: Password is appended to challenge string, response is MD5 hash of result.


