Re: New security extension: scripthash
| From: | Zeev Suraski | Date: | Sat, 02 Dec 2000 21:13:27 +0000 |
| Subject: | Re: New security extension: scripthash | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-39860@lists.php.net to get a copy of this message | ||
At 22:36 2/12/2000, John Sutton wrote:
Not quite sure what you are asking here! By "any sort of database" I don't suppose you mean ndbm as opposed to gdbm... Yes, a server has the passwords. The key question is: how can the server determine if the request for a particular password is legitimate? This extension is an attempt to solve that problem.I guess my question was 'how'. SQL databases attempt to do it using a user/password mechanism (it's true that with gdbm you won't have that kind of protection), but then, that's the mechanism you're trying to protect. How does scripthash do it? Zeev -- Zeev Suraski <zeev@zend.com> CTO, Zend Technologies Ltd. http://www.zend.com/