Re: Re: trans-sid warning?
| From: | Yasuo Ohgaki | Date: | Wed, 14 Aug 2002 11:08:18 +0000 |
| Subject: | Re: Re: trans-sid warning? | ||
| References: | 1 2 3 4 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-86811@lists.php.net to get a copy of this message | ||
Melvyn Sopacua wrote:
At 12:04 14-8-2002, Yasuo Ohgaki wrote:I thought we aren't talking about such case. We should provide appropriate level of protection/security depends of the information/requirements. Using URL based session management is probably ok for web based chat, but not for web based banking. -- Yasuo OhgakiAren't we discussing what method of passing session ID is less secure than others?Yes, but I fail to see what it has to do with security. For instance - I use sessions to store some output that takes a lot of time to generate. Why would that be a security risk for anyone?