Re: New security extension: scripthash

From: Date: Sat, 02 Dec 2000 21:13:27 +0000
Subject: Re: New security extension: scripthash
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-39860@lists.php.net to get a copy of this message
At 22:36 2/12/2000, John Sutton wrote:
Not quite sure what you are asking here! By "any sort of database" I don't suppose you mean ndbm as opposed to gdbm... Yes, a server has the passwords. The key question is: how can the server determine if the request for a particular password is legitimate? This extension is an attempt to solve that problem.
I guess my question was 'how'. SQL databases attempt to do it using a user/password mechanism (it's true that with gdbm you won't have that kind of protection), but then, that's the mechanism you're trying to protect. How does scripthash do it? Zeev -- Zeev Suraski <zeev@zend.com> CTO, Zend Technologies Ltd. http://www.zend.com/

« previous php.dev (#39860) next »