Is cfNTauthenticate a safe method for log-in ?
I have a Coldfusion application running (entirely written by other people, but that I'm kind of managing now) that uses the cfNTauthenticate tag for users to log-in, but now I have been asked to make sure that using this is safe.
I have read the official documentation of cfNTauthenticate, but it doesn't explain explicitly how the user name and password are authenticated against the NT domain.
I am rather new to Coldfusion and not an expert of Windows so I might not be understanding some things in the documentation, but it really doesn't seem to mention this.
The main question is, are the user name and password sent in clear to the Windows NT domain, or is it encrypted ?
If any of you have some information about this, that would be very interesting for me.
