Re: trans-sid warning?
| From: | Dan Hardiker | Date: | Wed, 14 Aug 2002 20:23:33 +0000 |
| Subject: | Re: trans-sid warning? | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-86847@lists.php.net to get a copy of this message | ||
> On the other hand, if you know the user's credentials, why bother to
> fake anything -- just log in to the system like anyone else!
Thats user security - only user training can do that.
> So... In a system where eavesdropping or man-in-the-middle attacks are
> not possible (ie. HTTP over SSL), HTTP Basic Authentication is secure.
As secure as any other method suggested [eg: cookies] yes - but no more or
less secure.
--
Dan Hardiker [dhardiker@staff.firstcreative.net]
ADAM Software & Systems Engineer
First Creative Ltd