RE: [PHP] WAYS OF AUTHENICATION - open discussion
| From: | Siim Einfeldt aka Itpunk | Date: | Wed, 08 Nov 2000 15:26:37 +0000 |
| Subject: | RE: [PHP] WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-24327@lists.php.net to get a copy of this message | ||
Thomas Deliduka thomas@neweve.com wrote:
>It's secured insofar as someone from outside the site can't include the
file
>via a url. But if htey have access to telnet to the server or got your
FTP
>password then it can be compromised, it's almost impossible (that I know
of)
>to be completely and utterly secure when it comes to those factors.
yes, that part goes to a bit different discussion. And if servers are
insecure then your web based superduper authentication systems have no
use.
>I was going to warn against using PASSWORD() in the db because you can't
>unencrypt that but you weren't going to need to unencrypt it. Assuming
md5
>is as good as it seems, sure, that sounds like a good plan.
i think so too.
>> Can we truly call it a drawback? The security matters, user
satisfaction
>True, in actuality it's not too much of a drawback, just a time-delay to
>have to change the password twice.
yes, little time delay but norhing else.
>I don't know, best security is put it behind an ssl layer. My methodology
I
>described before is used in a control panel that's behind a secure
server.
I could use some more information about it. maybe some more words from
you?
Siim Einfeldt
itpunk@itpunk.com