Re: Security and Cookies
| From: | Jeff P | Date: | Sat, 06 Jan 2001 03:54:50 +0000 |
| Subject: | Re: Security and Cookies | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-33005@lists.php.net to get a copy of this message | ||
Not secure at all.
In http, cookies are sent in the clear as part of
the http header -- anyone listening on the wire
can tell what values are set. The user can also
modify them easily (just open your local cookies
file with a text editor).
If you want no one to be able to listen to the
cookie, use https, which will encrypt the
transaction so that anyone on the wire won't be
able to read it (easily).
If you don't want the user to spoof as another
user, you can use a large random string and
associate it with the user on the server side (ie,
the user "proves" they are who they are with a
one-time (per session) token). This is too
complicated to explain in a quick paragraph...
but you probably don't want to implement it
yourself, since it's already been done for you.
Look at php-lib, which provides said session
tracking and user authentication.
If you don't want anyone to be able to listen to
the cookie and don't want a user to spoof as
another user, then use session cookies (a la
php-lib) over https.
best, jeff
> How secure is data stored in cookies? I use cookies to handle user
> authentication and session management. But I understand that cookies can
> be modified by users and perhaps they can pretend being someone else.
>
> I store the UserID on my cookies to display the corresponding user
> information. What precautions can I take to protect the other users of
> my site from this kind of breach?
>
> Thanks in advance..
>