MDN wants to talk to developers like you: https://qsurvey.mozilla.com/s3/8d22564490d8

Challenge-response authentication

In security protocols, a challenge is some data sent to the client by the server in order to generate a different response each time. Challenge-response protocols are one way to fight against replay attacks where an attacker listens to the previous messages and resends them at a later time to get the same credentials as the original message.

The HTTP authentication protocol is challenge-response based, though the "Basic" protocol isn't using a real challenge (the realm is always the same).

Learn more

Document Tags and Contributors

Tags: 
 Contributors to this page: fscholz, teoli
 Last updated by: fscholz,