Re: Session management module - thoughts
| From: | Sascha Schumann | Date: | Sat, 29 May 1999 10:39:25 +0000 |
| Subject: | Re: Session management module - thoughts | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-6236@lists.php.net to get a copy of this message | ||
On Fri, May 28, 1999 at 08:31:13PM -0500, Richard Lynch wrote:
>
> Either that, or y'all are on the same page and I'm not, and the session
> data is somehow automagically invisible to users on a shared PHP system.
>
> Also, it hasn't been explicitly stated (or I missed it), but I'm assuming
> the default unique session IDs will be unpredicatable to avoid
> man-in-the-middle attacks?... Please :-)
To avoid session hijacks (m-i-t-m attacks), users will have to use HTTP
secure. As I said before, a session system does not deal with security in the
sense of SSL/TLS.
The keys will be generated using MD5 since that is the only hash algorithm
which is guaranteed to be available in PHP.
Since MD5 produces rarely collisions, we could even allow ISPs to use only one
directory for storing keys. That would make the configuration part much
easier.
Of course, the ISP would have to forbid the access to this directory for
normal PHP users on their server to avoid stealing of session ids.
--
Regards,
Sascha Schumann
Consultant
--
PHP Development Mailing List http://www.php.net/
To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net
For help: php-dev-help@lists.php.net