Re: New security extension: scripthash

From: Date: Sat, 02 Dec 2000 20:36:36 +0000
Subject: Re: New security extension: scripthash
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-39857@lists.php.net to get a copy of this message
> I've taken a glance at your new package, and I have a couple of questions. > > First, I'd like to understand the rationale behind it. Essentially, what > you're doing there is moving the password out of the files, and into some > sort of a server. Is that true? Yes. > If so, wouldn't any sort of database do? Don't get me wrong, the idea of > doing something about this issue is interesting, I just want to figure out > if what you're doing really increases security, or only moves it around a > bit... Not quite sure what you are asking here! By "any sort of database" I don't suppose you mean ndbm as opposed to gdbm... Yes, a server has the passwords. The key question is: how can the server determine if the request for a particular password is legitimate? This extension is an attempt to solve that problem. > The 2nd question - you refer to mysql_password() in your documentation, and > I can't seem to find where it's defined... It's defined in scripthash.php which will have been installed in /usr/lib/php by the install. Otherwise just get it from the tar in the apps directory. *************************************************** John Sutton SCL Computer Services URL http://www.scl.co.uk/ Tel. +44 (0) 1239 621021 ***************************************************

« previous php.dev (#39857) next »