RE: [PHP] WAYS OF AUTHENICATION - open discussion

From: Date: Wed, 08 Nov 2000 15:26:37 +0000
Subject: RE: [PHP] WAYS OF AUTHENICATION - open discussion
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-24327@lists.php.net to get a copy of this message
Thomas Deliduka thomas@neweve.com wrote: >It's secured insofar as someone from outside the site can't include the file >via a url. But if htey have access to telnet to the server or got your FTP >password then it can be compromised, it's almost impossible (that I know of) >to be completely and utterly secure when it comes to those factors. yes, that part goes to a bit different discussion. And if servers are insecure then your web based superduper authentication systems have no use. >I was going to warn against using PASSWORD() in the db because you can't >unencrypt that but you weren't going to need to unencrypt it. Assuming md5 >is as good as it seems, sure, that sounds like a good plan. i think so too. >> Can we truly call it a drawback? The security matters, user satisfaction >True, in actuality it's not too much of a drawback, just a time-delay to >have to change the password twice. yes, little time delay but norhing else. >I don't know, best security is put it behind an ssl layer. My methodology I >described before is used in a control panel that's behind a secure server. I could use some more information about it. maybe some more words from you? Siim Einfeldt itpunk@itpunk.com

« previous php.general (#24327) next »