note 36058 deleted from features.cookies by salathe
| From: | salathe@php.net | Date: | Mon, 21 Sep 2020 14:35:08 +0000 |
| Subject: | note 36058 deleted from features.cookies by salathe | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-215209@lists.php.net to get a copy of this message | ||
Note Submitter: myfirstname at braincell dot cx
----
[Editor's note: Wilson's comment has been deleted since it didn't contain much useful
information, but this note is preserved although its reference is lost]
Just a general comment on Wilton's code snippet: It's generally considered very bad
practice to store usernames and/or passwords in cookies, whether or not they're obsfucated.
Many spyware programs make a point of stealing cookie contents.
A much better solution would be to either use the PHP built in session handler or create something
similar using your own cookie-based session ID. This session ID could be tied to the source IP
address or can be timed out as required but since the ID can be expired separately from the
authentication criteria the authentication itself is not compromised.
Stuart Livings