Re: Security and Cookies

From: Date: Sat, 06 Jan 2001 03:54:50 +0000
Subject: Re: Security and Cookies
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-33005@lists.php.net to get a copy of this message
Not secure at all. In http, cookies are sent in the clear as part of the http header -- anyone listening on the wire can tell what values are set. The user can also modify them easily (just open your local cookies file with a text editor). If you want no one to be able to listen to the cookie, use https, which will encrypt the transaction so that anyone on the wire won't be able to read it (easily). If you don't want the user to spoof as another user, you can use a large random string and associate it with the user on the server side (ie, the user "proves" they are who they are with a one-time (per session) token). This is too complicated to explain in a quick paragraph... but you probably don't want to implement it yourself, since it's already been done for you. Look at php-lib, which provides said session tracking and user authentication. If you don't want anyone to be able to listen to the cookie and don't want a user to spoof as another user, then use session cookies (a la php-lib) over https. best, jeff > How secure is data stored in cookies? I use cookies to handle user > authentication and session management. But I understand that cookies can > be modified by users and perhaps they can pretend being someone else. > > I store the UserID on my cookies to display the corresponding user > information. What precautions can I take to protect the other users of > my site from this kind of breach? > > Thanks in advance.. >

« previous php.general (#33005) next »