Secure Authentication Without a Secure Connection (SAWASC)

Get It

The SAWASC Specification is available in the following formats (Click to view):

HTML

PDF

OpenDocument Text

If you need software to read the OpenDocument Text format, may I recommend OpenOffice.org.

Current Version

The current version of the SAWASC Specification is version 1.1 Third Edition. This is the fourth public release of the specification.

Purpose

The purpose of the SAWASC specification is to provide developers with a clear, concise, and organised method of both authenticating users to their system and authenticating their system to its users without transmitting passwords in plain text.

A system which complies to the SAWASC Specification is much less vulnerable to packet sniffers discovering user passwords and phishing attacks.

History

SAWASC has the same basic design as the Challenge Handshake Authentication Protocol. It was designed with the same principles. However, a few features make it much easier to implement on world wide web based systems.

Version History

1.1 (3rd Edition): HTML - PDF - ODT

1.1 (2nd Edition): HTML - PDF - ODT

1.1 (1st Edition): HTML - PDF - ODT

1.0 (1st Edition): HTML - PDF - ODT