Re: WAYS OF AUTHENICATION - open discussion

From: Date: Sat, 04 Nov 2000 09:30:02 +0000
Subject: Re: WAYS OF AUTHENICATION - open discussion
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-23690@lists.php.net to get a copy of this message
Don't make mysql users. That is wrong. The first and second ideas are the correct ones whether you do hand written sessions or use PHP4. The part that I think you are missing is that the "session" is a unique key so to speak that lets the user be active. Another part is that this table that holds the sessions usually gets cleaned out by something running in cron -- basically nuking any "expired" sessions. This prevents what you have stated, that if soneone knew the session, they can get in. They can't match the session var to the table if the session is gone from the table. They may be expired for any number of reasons, but usually it is because they become inactive, or a user has logged in from another browser. Hope this helps. -jeremy brand _______________________________________________________________________ GnuPG Fingerprint: 9F5E 95E0 1CC2 E054 84EA 6099 8ACD 9DBA D2C0 5EA9 _ http://www.JeremyBrand.com/Jeremy/Brand/Jeremy_Brand.html for more __ On Sat, 4 Nov 2000, Siim Einfeldt aka Itpunk wrote: > Date: Sat, 4 Nov 2000 11:19:26 +0200 (EET) > From: Siim Einfeldt aka Itpunk <siim_e@pshg.edu.ee> > To: php-general-digest-help@lists.php.net > Cc: php-general@lists.php.net > Subject: [PHP] WAYS OF AUTHENICATION - open discussion > > > I`m interested in different ways of authentication, their plusses and > minuses. On way is just to create a sessionid, get the useragent, ip and > when someone logs in, the stuff is written to a database and is checked on > every refresh, also some created time is checked if the user has been idle > for more than half an hour. If the information is still correct, the users > stays in, if it`s not correct anymore, he will be directed to the login > page. What do you think, how secure this is? > > The problem that I see with the previous example, is that if someone knew > the variable name, which connects to the database, usually people use $db, > if you know it, you can just include the file in which the mysql_connect > takes place and you will get to know the username and password. I haven`t > tried it, but am I right? Is this that simple? And if it is, what could I > do about it? > > Second way of authentication is with php4 built-in sessions. But the > previously mentioned problem stays here too. And how would you rate the > php4 built-in sessions compared to self-created sessionid`s. Yes, they > give the opportunity to keep the address bar clean by keeping the > variables in sessions, but are there any big differences in security > level? > > Third, in some ways it seems to me the securiest way, is making all the > users mysql users. The sessionid stuff has to be chosen from already > mentioned things, but the connect variables aren`t so insecure anymore as > the user information is written directly to the mysql database/user table > instead of some self-created users table. This way there`s no prewritten > usernames and/or passwords to discover, because the user name and password > depends totally on what the user types to the login input fields. > > I`d like to know your opionion about all these mentioned ways of > authentication and idealy you would add some good ones, as well as bring > out their good and bad points. And what might be the securiest way of > authentication? What aspects should be thought about before starting to > build a new authentication system? What are the main problems we have to > face? So the topic is Security with big S. > > P.S. Please, when answering to this, send a copy to my personal email as > well. > > > Siim Einfeldt > ----------------------------------------------------------------------------- > If we don`t do it now, we will never do it,//////////////////////////// > ////////////////////////////if we will never do it, we`re going to miss it. > ----------------------------------------------------------------------------- > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.general (#23690) next »