Re: New security extension: scripthash
| From: | John Sutton | Date: | Sat, 02 Dec 2000 20:36:36 +0000 |
| Subject: | Re: New security extension: scripthash | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-39857@lists.php.net to get a copy of this message | ||
> I've taken a glance at your new package, and I have a couple of questions.
>
> First, I'd like to understand the rationale behind it. Essentially, what
> you're doing there is moving the password out of the files, and into some
> sort of a server. Is that true?
Yes.
> If so, wouldn't any sort of database do? Don't get me wrong, the idea of
> doing something about this issue is interesting, I just want to figure out
> if what you're doing really increases security, or only moves it around a
> bit...
Not quite sure what you are asking here! By "any sort of database" I don't
suppose you mean ndbm as opposed to gdbm...
Yes, a server has the passwords. The key question is: how can the server
determine if the request for a particular password is legitimate? This
extension is an attempt to solve that problem.
> The 2nd question - you refer to mysql_password() in your documentation, and
> I can't seem to find where it's defined...
It's defined in scripthash.php which will have been installed in /usr/lib/php
by the install. Otherwise just get it from the tar in the apps directory.
***************************************************
John Sutton
SCL Computer Services
URL http://www.scl.co.uk/
Tel. +44 (0) 1239 621021
***************************************************