Re: Session management module - thoughts

From: Date: Sat, 29 May 1999 10:39:25 +0000
Subject: Re: Session management module - thoughts
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-6236@lists.php.net to get a copy of this message
On Fri, May 28, 1999 at 08:31:13PM -0500, Richard Lynch wrote: > > Either that, or y'all are on the same page and I'm not, and the session > data is somehow automagically invisible to users on a shared PHP system. > > Also, it hasn't been explicitly stated (or I missed it), but I'm assuming > the default unique session IDs will be unpredicatable to avoid > man-in-the-middle attacks?... Please :-) To avoid session hijacks (m-i-t-m attacks), users will have to use HTTP secure. As I said before, a session system does not deal with security in the sense of SSL/TLS. The keys will be generated using MD5 since that is the only hash algorithm which is guaranteed to be available in PHP. Since MD5 produces rarely collisions, we could even allow ISPs to use only one directory for storing keys. That would make the configuration part much easier. Of course, the ISP would have to forbid the access to this directory for normal PHP users on their server to avoid stealing of session ids. -- Regards, Sascha Schumann Consultant -- PHP Development Mailing List http://www.php.net/ To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net For help: php-dev-help@lists.php.net

« previous php.dev (#6236) next »