Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Mon, 06 Nov 2000 19:59:56 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1 2 3 4 5 6 7  Groups: php.general 
Request: Send a blank email to php-general+get-23973@lists.php.net to get a copy of this message
> > Well, of course you're right, but this *is* better than a plaintext login. > > And I offer my login on SSL, so users can use that if they're really > > paranoid. In any case, you have to weigh all the factors, and the simple > > fact is that there's no good reason to break into one of my user's accounts; > > you can't do anything useful with it. Being somewhat paranoid, I merely > > wanted to give my users something *more* secure than plaintext logins until > > I got my SSL site working. > > Agreed, it's important to balance necessity, security > and convenience. I'm the most paranoid person ever, so nothing > is secure enough for me :) > > Please don't get me wrong, I'm playing the devil's > advocate here. I try to offer constructive criticism and you > can be sure that I am very interested in the answers I get, > not in criticizing others' ideas. > > Now, being the paranoid type I am, I am all for SSL. > This way I don't have to reinvent (much ) the wheel. Then I > store the md5 hashes of my users' passwords in the database > and send both userid and password in the clear, SSL takes > care of the rest. Well, of course you're right. SSL is the best way to have true security on the web. My problem is getting a certificate signed. I have no money, so I'm going to have to do some heavy research into the innerworkings of open_ssl, so I can start my own certificate authority to sign my certificates. This way, my users can add my root cert to their browsers and all will be okey-dokey. I think once I get this done, I'll get rid of my insecure login. In the meantime, I'll offer it, because my certs are all outdated, and there's no way to authenticate that the cert is from me. I'll have to come up with some way to deliver my root cert so and authenticate it from the website, but it'll be worth it. Dean.

« previous php.general (#23973) next »