Php4 Session Data Format
| From: | Mark Kirkwood | Date: | Thu, 17 Aug 2000 04:21:25 +0000 |
| Subject: | Php4 Session Data Format | ||
| Groups: | php.db | ||
| Request: | Send a blank email to php-db+get-2112@lists.php.net to get a copy of this message | ||
Hi all,
I was thinking about the fact that php4 session data is stored essentially in plain text ( by
default ).
I realize that the session store ( whether it be files / db / shmem etc ) can be protected to
minimize the access of snoopers, but I wondered if it would be worthwhile encrypting the data by
default.
I am considering brutalizing my custom Postgres session handler to see if I can include this sort of
thing ( maybe using mcrypt ..? ), but thought the encryption issue was worth raising even for the
default handler....
regards
Mark Kirkwood
mark.kirkwood@hnz.co.nz