Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | Dean Hall | Date: | Mon, 06 Nov 2000 18:58:57 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 3 4 5 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23953@lists.php.net to get a copy of this message | ||
> > Okay, one thing I forgot to mention is that there is a time limit of one
> > minute on how long the user can take to log in. If there was no such
time
> > limit, you would be correct. With this time limit, if someone can listen
in
> > and get the hash in that time span, yes, you can.
>
> Aha ... and I don't think it's too difficult to do so. The whole
> attack can be automated.
>
> Manuel Garcia
Well, of course you're right, but this *is* better than a plaintext login.
And I offer my login on SSL, so users can use that if they're really
paranoid. In any case, you have to weigh all the factors, and the simple
fact is that there's no good reason to break into one of my user's accounts;
you can't do anything useful with it. Being somewhat paranoid, I merely
wanted to give my users something *more* secure than plaintext logins until
I got my SSL site working.
So, you've offered your critiques; how about sharing what you would propose
for user authentication? It's nice to share some information as opposed to
just criticizing others' ideas. :-)
Dean.