Re: Authentication

From: Date: Thu, 04 Jul 2002 20:22:46 +0000
Subject: Re: Authentication
Groups: php.general 
Request: Send a blank email to php-general+get-105506@lists.php.net to get a copy of this message
>Thanks, I guess I'll just do that. I was actually wondering how to leave >this barrier up without being nasty to normal users. That also solves >the dial-up problem, at least much of it, as callers will fluctuate >mostly on the last octet if they do reconnect through the same ISP, >right? Depends how big the ISP is... These days, you really can't count on anything with the IP address. >Besides, IP masquerading gateways ARE a problem with the >suggestion I gave. And I guess this also explains why we are having so >much trouble in counting users (that is, IPs) whenever ADSL connection >come around. Any suggestion? Install software that was designed to do it... Innumerable log analysis software packages exist. Don't re-invent the wheel. Or, forget IP, and force every user to log in. I bet that some of those stupid annoying sites requiring an email/password combo are doing it *just* to count users properly. >So you mean I have a 32 byte MD5 session id to identify the current >visit, plus another such thing to identify the step within it, right? If I'm on Step 5, and then I'm on step 6, and then I'm on Step 6, one of the two Step 6 attempts is probably a "hijack"... Or I hit "Back". Or "Reload", maybe, depending on how you code it. -- Like Music? http://l-i-e.com/artists.htm

« previous php.general (#105506) next »