Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Mon, 06 Nov 2000 19:23:56 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1 2 3 4 5 6  Groups: php.general 
Request: Send a blank email to php-general+get-23964@lists.php.net to get a copy of this message
=== Dean Hall escribia (Mon, Nov 06, 2000 at 12:58:57PM -0600): > > > Okay, one thing I forgot to mention is that there is a time limit of one > > > minute on how long the user can take to log in. If there was no such > time > > > limit, you would be correct. With this time limit, if someone can listen > in > > > and get the hash in that time span, yes, you can. > > > > Aha ... and I don't think it's too difficult to do so. The whole > > attack can be automated. > > > > Manuel Garcia > > Well, of course you're right, but this *is* better than a plaintext login. > And I offer my login on SSL, so users can use that if they're really > paranoid. In any case, you have to weigh all the factors, and the simple > fact is that there's no good reason to break into one of my user's accounts; > you can't do anything useful with it. Being somewhat paranoid, I merely > wanted to give my users something *more* secure than plaintext logins until > I got my SSL site working. Agreed, it's important to balance necessity, security and convenience. I'm the most paranoid person ever, so nothing is secure enough for me :) > So, you've offered your critiques; how about sharing what you would propose > for user authentication? It's nice to share some information as opposed to > just criticizing others' ideas. :-) Please don't get me wrong, I'm playing the devil's advocate here. I try to offer constructive criticism and you can be sure that I am very interested in the answers I get, not in criticizing others' ideas. Now, being the paranoid type I am, I am all for SSL. This way I don't have to reinvent (much ) the wheel. Then I store the md5 hashes of my users' passwords in the database and send both userid and password in the clear, SSL takes care of the rest. It's my turn now ;) > > Dean. > Manuel Garcia

« previous php.general (#23964) next »