RE: [PHP] Secure user authentication
| From: | Brian McGarvie | Date: | Fri, 03 May 2002 14:20:07 +0000 |
| Subject: | RE: [PHP] Secure user authentication | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-95900@lists.php.net to get a copy of this message | ||
my current project for a multi-national org is providing a service to
them which requires that, I also go a stage further and allow only ip's
from their domain for this site ;) as well as SSL, and my own form of
encryption.
-----Original Message-----
From: The_RadiX [mailto:the_radix@hotkey.net.au]
Sent: 03 May 2002 15:14
To: php-general@lists.php.net; Brian McGarvie
Subject: Re: [PHP] Secure user authentication
that is a good suggestion..
Using SSL to perform "sensitive" logins.. and then using some sort of
"hidden" or "encrypted" passwords in your sessions should provide a nice
level of security and comfort..
:::::::::::::::::::::::::::::::::::::::::::
: Julien Bonastre [The-Spectrum.org CEO]
: A.K.A. The_RadiX
: the_radix@hotkey.net.au
: ABN: 64 235 749 494
: QUT Student :: 04475739
:::::::::::::::::::::::::::::::::::::::::::
----- Original Message -----
From: "Brian McGarvie" <bmcgarvie@lennox-mckinlay.co.uk>
To: <php-general@lists.php.net>
Sent: Saturday, May 04, 2002 12:12 AM
Subject: RE: [PHP] Secure user authentication
another option is to use SSL for the login page/sensitive parts of the
site that deal with any transfer of 'sensitive' data?
-----Original Message-----
From: Jon Haworth [mailto:jhaworth@witanjardine.co.uk]
Sent: 03 May 2002 15:08
To: 'The_RadiX'; php-general@lists.php.net
Subject: RE: [PHP] Secure user authentication
Hi,
> but the password is put through my own fairly unbreakable
> (yes.. I am serious) password key system..
> SO basically you'll end up with a nice 32 char string
> which is QUITE safe to pass around and the chance anyone's
> gonna decrypt it IMHO is about zilch,
> And all you have to do, is when they login once, just run
> the password they entered through this "algorithm" and
> check it against the stored algo'd password..
Presumably you have a Javascript implementation of your algorithm, which
runs on the login page - otherwise you'd just be transmitting the
password
in clear text from the browser to the server, right?
If you don't do this, how do you deal with getting the password from the
user to the server so you can authenticate them?
If you do, how do you deal with people who have Javascript disabled?
Cheers
Jon
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php