Re: trans-sid warning?
| From: | Marko Karppinen | Date: | Wed, 14 Aug 2002 20:14:24 +0000 |
| Subject: | Re: trans-sid warning? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-86845@lists.php.net to get a copy of this message | ||
Dan Hardiker:
However, HTTP basic authentication is passed the same as session cookies (discussed earlier in this thread) - in the headers of the HTTP communication. This can very easily be faked with something like cURL.On the other hand, if you know the user's credentials, why bother to fake anything -- just log in to the system like anyone else! So... In a system where eavesdropping or man-in-the-middle attacks are not possible (ie. HTTP over SSL), HTTP Basic Authentication is secure. So it makes sense the piggybag the session id propagation on it also. mk