Re: trans-sid warning?
| From: | Dan Hardiker | Date: | Wed, 14 Aug 2002 15:15:05 +0000 |
| Subject: | Re: trans-sid warning? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-86830@lists.php.net to get a copy of this message | ||
> + <para>
> + Therefore, when dealing with sensative information, there should +
> always be additional methods to decide whether it is a valid +
> session. Sessions are <strong>not reliable</strong> as a secure +
> authentication mechanism.
> + </para>
So if Im to write an online web-based banking system (either in Java/JSP,
PHP, ASP - whatever)... what method would you suggest that IS secure?
--
Dan Hardiker [dhardiker@staff.firstcreative.net]
ADAM Software & Systems Engineer
First Creative Ltd