Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | Dean Hall | Date: | Mon, 06 Nov 2000 19:59:56 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23973@lists.php.net to get a copy of this message | ||
> > Well, of course you're right, but this *is* better than a plaintext
login.
> > And I offer my login on SSL, so users can use that if they're really
> > paranoid. In any case, you have to weigh all the factors, and the simple
> > fact is that there's no good reason to break into one of my user's
accounts;
> > you can't do anything useful with it. Being somewhat paranoid, I merely
> > wanted to give my users something *more* secure than plaintext logins
until
> > I got my SSL site working.
>
> Agreed, it's important to balance necessity, security
> and convenience. I'm the most paranoid person ever, so nothing
> is secure enough for me :)
>
> Please don't get me wrong, I'm playing the devil's
> advocate here. I try to offer constructive criticism and you
> can be sure that I am very interested in the answers I get,
> not in criticizing others' ideas.
>
> Now, being the paranoid type I am, I am all for SSL.
> This way I don't have to reinvent (much ) the wheel. Then I
> store the md5 hashes of my users' passwords in the database
> and send both userid and password in the clear, SSL takes
> care of the rest.
Well, of course you're right. SSL is the best way to have true security on
the web. My problem is getting a certificate signed. I have no money, so I'm
going to have to do some heavy research into the innerworkings of open_ssl,
so I can start my own certificate authority to sign my certificates. This
way, my users can add my root cert to their browsers and all will be
okey-dokey. I think once I get this done, I'll get rid of my insecure login.
In the meantime, I'll offer it, because my certs are all outdated, and
there's no way to authenticate that the cert is from me. I'll have to come
up with some way to deliver my root cert so and authenticate it from the
website, but it'll be worth it.
Dean.