Resently is am tasked to rewrite a login system for a winform to only use a key as auth. The customer is imagin a flow like
- download exe file
- Get a key (guid look alike in mail)
- activate u exe and run app.
Not that hard just send the key to the server validate it and boom u got a login.
But is this really secure i mean with a login using password and username i can look the user up by his name and validate a hased edition of his pasword. that way i only pass username and hased version of password.
With only the key how do i pass that from the client to the server secure, and still being able of validating agains the user database.
I have a https and some ssh certificates avalible on the auth server.
thx in advanced