Re: trans-sid warning?
| From: | George Schlossnagle | Date: | Tue, 20 Aug 2002 00:28:48 +0000 |
| Subject: | Re: trans-sid warning? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-87112@lists.php.net to get a copy of this message | ||
On Monday, August 19, 2002, at 07:56 PM, Rasmus Lerdorf wrote:
To play devil's advocate, pure cookie based authentication is not a panacea. If you allow users to put things like javascript on your site, or if you have users who exploit ie bugs like the about: cookie domain bug from last year, cookies can be stolen and session hijacked. pure cookie auth is definitely a good thing, but does not provide safety in a number of 'real world' applications. GeorgeI do agree with that, I just wasn't convinced that it was a useful feature.To conclude: Don't trade useful features for pseudo security. Removing this feature just increases the feeling of having a 'secure' site and decreases the desire to protect oneself by activating session.use_only_cookies.