Security. Cookies or ?...
| From: | David VanHorn | Date: | Sun, 02 Jul 2000 00:43:29 +0000 |
| Subject: | Security. Cookies or ?... | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-4328@lists.php.net to get a copy of this message | ||
Currently, my users have a 10 digit account number that they must enter to authenticate themnselves.
I also look at the IP where the transaction is originating, and compare that to a valid range tied to their account.
The numbers are "clunky", but effective.
I've shied away from cookies because I don't understand them, and I think it might be possible to build a web page to suck out cookie info from a browser (presenting itself as my domain)
My users would be particularly vulnerable to that sort of attack, as they are the anti-spam cops.
Comments, suggestions, pointers?
:)
--
www.SpamWhack.com A pre-emptive strike against spam
A tornado is a lady whose skirts you do NOT want to look up!
Where's dave? http://www.findu.com/cgi-bin/find.cgi?kc6ete-9