Re: security question/help
| From: | Michael Kimsal | Date: | Wed, 20 Sep 2000 14:10:26 +0000 |
| Subject: | Re: security question/help | ||
| References: | 1 2 3 4 5 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-17239@lists.php.net to get a copy of this message | ||
No problem. Couple ideas on the randomness -
you could include an md5hash of the remote_addr in the
other random string, making it a bit more unique. Re: people
copying cookies - are these cookies that will be persistent
across days?
We've got a situation with cookies being used for identity,
but we force people to log in every time, and create a new cookie
for them at that point. There's not much chance of someone
copying the cookie to another machine, because the session
info it's tied to expires after a bit.
If you're after more permanent IDs via cookies this might not
help much tho.
Best of luck on this project, and feel free to bounce ideas of me
or (I'm assuming) others on this list as well. :)
Later...
Charles Killian wrote:
> Michael, thanks for your help.
> I am using cookies to keep client sessions and damn all those who don't love
> a good oreo. But my main reason for correlating another bit of information
> with the unique cookie is for security. I'm being very paranoid here
> because this will probably never happen but I want to defend against a user
> copying a cookie or the case of a random cookie not being so random.
>
> I'm scraping the idea of storing the remote_addr. AOL's documentation and
> warnings convinced me otherwise.
>
> Thanks again,
> charles
--
==========================
Michael Kimsal
http://www.tapinternet.com
734-480-9961