Re: Session management module - thoughts

From: Date: Sat, 29 May 1999 01:31:13 +0000
Subject: Re: Session management module - thoughts
Groups: php.dev 
Request: Send a blank email to php-dev+get-6231@lists.php.net to get a copy of this message
I'm also not sure that there shouldn't be some easy way to encrypt/decrypt the data that is stored. One could readily imagine that it would be really nifty for Joe Six-Pack web-developer to want to keep a credit card number for a regular customer in the files... Or, in the case of an ISP configuring the storage location, it would then presumably be accessible to all PHP users on the same system, if they could guess at your session IDs. That would be bad. Finally, a lot of times the ISP is not *that* well-versed in PHP. They install it to have another bullet point [rather like the reason for adding this feature :-)] but worrying about their users crossing over each other in a shared session management file would not be on their radar unless it's real clear during install/configure. I realize this is a whole 'nother can of worms to open up, but it seems to me that a large percentage of requests for session tracking come about as a result of security and ecommerce concerns. Either that, or y'all are on the same page and I'm not, and the session data is somehow automagically invisible to users on a shared PHP system. Also, it hasn't been explicitly stated (or I missed it), but I'm assuming the default unique session IDs will be unpredicatable to avoid man-in-the-middle attacks?... Please :-) -- "TANSTAAFL" Rich lynch@cognitivearts.com webmaster@ and www. all of: R&B/jazz/blues/rock - jademaze.com music industry org - chatmusic.com acoustic/funk/world-beat - astrakelly.com sculptures - olivierledoux.com my own nascent company - l-i-e.com cool coffeehouse - uncommonground.com -- PHP Development Mailing List http://www.php.net/ To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net For help: php-dev-help@lists.php.net

« previous php.dev (#6231) next »