Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | Manuel Enrique Garcia Cuesta | Date: | Mon, 06 Nov 2000 19:23:56 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 3 4 5 6 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23964@lists.php.net to get a copy of this message | ||
=== Dean Hall escribia
(Mon, Nov 06, 2000 at 12:58:57PM -0600):
> > > Okay, one thing I forgot to mention is that there is a time limit of one
> > > minute on how long the user can take to log in. If there was no such
> time
> > > limit, you would be correct. With this time limit, if someone can listen
> in
> > > and get the hash in that time span, yes, you can.
> >
> > Aha ... and I don't think it's too difficult to do so. The whole
> > attack can be automated.
> >
> > Manuel Garcia
>
> Well, of course you're right, but this *is* better than a plaintext login.
> And I offer my login on SSL, so users can use that if they're really
> paranoid. In any case, you have to weigh all the factors, and the simple
> fact is that there's no good reason to break into one of my user's accounts;
> you can't do anything useful with it. Being somewhat paranoid, I merely
> wanted to give my users something *more* secure than plaintext logins until
> I got my SSL site working.
Agreed, it's important to balance necessity, security
and convenience. I'm the most paranoid person ever, so nothing
is secure enough for me :)
> So, you've offered your critiques; how about sharing what you would propose
> for user authentication? It's nice to share some information as opposed to
> just criticizing others' ideas. :-)
Please don't get me wrong, I'm playing the devil's
advocate here. I try to offer constructive criticism and you
can be sure that I am very interested in the answers I get,
not in criticizing others' ideas.
Now, being the paranoid type I am, I am all for SSL.
This way I don't have to reinvent (much ) the wheel. Then I
store the md5 hashes of my users' passwords in the database
and send both userid and password in the clear, SSL takes
care of the rest.
It's my turn now ;)
>
> Dean.
>
Manuel Garcia