Authentication
| From: | Peter | Date: | Wed, 03 Jul 2002 19:32:06 +0000 |
| Subject: | Authentication | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-105269@lists.php.net to get a copy of this message | ||
On my site, when a user logs in, their password is encrypted using md5() and
the username and encrypted password is then passed from page to page using
hidden form inputs (clicking on a link submits the form using POST).
Does anyone have any comments on this method e.g. security wise? I know I
could use sessions or cookies but is it relly necessary?