Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Mon, 06 Nov 2000 20:21:58 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1 2 3 4 5 6 7 8  Groups: php.general 
Request: Send a blank email to php-general+get-23963@lists.php.net to get a copy of this message
Yes, this is typically secure enough for most intranet and low grade sites IMHO. Obviously if you're going to be doing transactions or need to eliminate man in the middle attacks then the only way to go is SSL. To clarify the snipped text shown below from my original post, I think it's easier to swipe the logon page and modify the form input than to setup something that sends a 401 response (is that right code for browserauth?) back to the target server a cracker is trying to get into. -- Scott On Mon, Nov 06, 2000 at 08:04:25PM +0100, Manuel Enrique Garcia Cuesta wrote: > > > === scottrus@ipass.net escribia > (Mon, Nov 06, 2000 at 10:18:57AM -0500): > > > Also, regarding user auth, I think the best way is to use basic browser authentication > > through php. It's a bit more complex to write in some cases but it helps eliminate > > people swiping the login form and trying to hack it to by pass the auth check. > > It surely cannot be that, but I have to ask. By basic > browser authentication you mean letting the browser base64-scramble > user+password ? > > > > > -- Scott > > Manuel Garcia > -- Scott

« previous php.general (#23963) next »