Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Weirdly, Windows makes it easier to do this securely in that you can do NTLM authentication to authenticate local users (maybe MacOS as well, I believe internally it runs its own Kerberos server for the local machine).


AFAIK you can only do this if you disable the local loopback check that prevents windows auth from passing credentials to local host webservers.


Why did they put that in in the first place? To stop cracking of local passwords?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: