RE: [PHP] Checking for cookies/session_existance.. very basic.
| From: | php3 at developersdesk dot com | Date: | Thu, 30 Nov 2000 10:10:49 +0000 |
| Subject: | RE: [PHP] Checking for cookies/session_existance.. very basic. | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-28003@lists.php.net to get a copy of this message | ||
Addressed to: Chad Day <cday@beachassociates.com>
"'php-general@lists.php.net'" <php-general@lists.php.net>
** Reply to note from Chad Day <cday@beachassociates.com> Wed, 29 Nov 2000 15:42:39 -0500
> If I force cookies like you said, someone can write a perl/php shell
> script to automatically delete the cookie, and vote again.
It is worse than that...
All I have to do in Netscape is disable cookies, save the change, re-enable
cookies, save the change, and vote again as often as I want. I don't have
to write anything. I could also exit netscape, and edit my cookies.txt file
and remove your entry to vote again.
> If I store the users IP, time, and picture ID in a table, that table
> would grow very large very fast, and the time it would take to do an
> SELECT than an INSERT on it would probably be adding too much overhead.
You would also disable lots of unintended people. One famous example, all
the users on AOL come in through a small number of proxy servers. Once
someone has voted from each of the proxy servers, you will be cutting off
everyone else on AOL. Many companies use proxy servers, and you would be
allowing only one vote from each.
Most ISP _modems_ have fixed IP addresses. That means that if I dial in
through modem #150 and vote, then hang up, anyone else who connects through
that modem will not be able to. I will also be able to hang up,
re-connect to a different modem and vote again.
As to what will work, good luck. I usually use email verification where I
would send them an email that they have to reply to. Even that has a
problem for your application. While I know the vote came from a valid
email address, nothing stops an abuser from registering a hundred email
addresses on Yahoo, and voting a hundred times.
After the problems with the current American election I expect to hear a
call for Internet voting. I only see the security problems that would
present. The current system leaves a paper trail that can be verified
after the fact. An Internet vote is way too easy to corrupt.
Rick Widmer
Internet Marketing Specialists
http://www.developersdesk.com