WAYS OF AUTHENICATION - open discussion
| From: | Siim Einfeldt aka Itpunk | Date: | Sat, 04 Nov 2000 09:19:26 +0000 |
| Subject: | WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23689@lists.php.net to get a copy of this message | ||
I`m interested in different ways of authentication, their plusses and
minuses. On way is just to create a sessionid, get the useragent, ip and
when someone logs in, the stuff is written to a database and is checked on
every refresh, also some created time is checked if the user has been idle
for more than half an hour. If the information is still correct, the users
stays in, if it`s not correct anymore, he will be directed to the login
page. What do you think, how secure this is?
The problem that I see with the previous example, is that if someone knew
the variable name, which connects to the database, usually people use $db,
if you know it, you can just include the file in which the mysql_connect
takes place and you will get to know the username and password. I haven`t
tried it, but am I right? Is this that simple? And if it is, what could I
do about it?
Second way of authentication is with php4 built-in sessions. But the
previously mentioned problem stays here too. And how would you rate the
php4 built-in sessions compared to self-created sessionid`s. Yes, they
give the opportunity to keep the address bar clean by keeping the
variables in sessions, but are there any big differences in security
level?
Third, in some ways it seems to me the securiest way, is making all the
users mysql users. The sessionid stuff has to be chosen from already
mentioned things, but the connect variables aren`t so insecure anymore as
the user information is written directly to the mysql database/user table
instead of some self-created users table. This way there`s no prewritten
usernames and/or passwords to discover, because the user name and password
depends totally on what the user types to the login input fields.
I`d like to know your opionion about all these mentioned ways of
authentication and idealy you would add some good ones, as well as bring
out their good and bad points. And what might be the securiest way of
authentication? What aspects should be thought about before starting to
build a new authentication system? What are the main problems we have to
face? So the topic is Security with big S.
P.S. Please, when answering to this, send a copy to my personal email as
well.
Siim Einfeldt
-----------------------------------------------------------------------------
If we don`t do it now, we will never do it,////////////////////////////
////////////////////////////if we will never do it, we`re going to miss it.
-----------------------------------------------------------------------------