Authentication

From: Date: Wed, 03 Jul 2002 19:32:06 +0000
Subject: Authentication
Groups: php.general 
Request: Send a blank email to php-general+get-105269@lists.php.net to get a copy of this message
On my site, when a user logs in, their password is encrypted using md5() and the username and encrypted password is then passed from page to page using hidden form inputs (clicking on a link submits the form using POST). Does anyone have any comments on this method e.g. security wise? I know I could use sessions or cookies but is it relly necessary?

« previous php.general (#105269) next »