note 36058 modified in features.cookies by victor

From: Date: Sat, 27 Mar 2004 20:10:33 +0000
Subject: note 36058 modified in features.cookies by victor
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-67243@lists.php.net to get a copy of this message
[Editor's note: Wilson's comment has been deleted since it didn't contain much useful information, but this note is preserved although its reference is lost] Just a general comment on Wilton's code snippet: It's generally considered very bad practice to store usernames and/or passwords in cookies, whether or not they're obsfucated. Many spyware programs make a point of stealing cookie contents. A much better solution would be to either use the PHP built in session handler or create something similar using your own cookie-based session ID. This session ID could be tied to the source IP address or can be timed out as required but since the ID can be expired separately from the authentication criteria the authentication itself is not compromised. Stuart Livings --was-- Just a general comment on Wilton's code snippet: It's generally considered very bad practice to store usernames and/or passwords in cookies, whether or not they're obsfucated. Many spyware programs make a point of stealing cookie contents. A much better solution would be to either use the PHP built in session handler or create something similar using your own cookie-based session ID. This session ID could be tied to the source IP address or can be timed out as required but since the ID can be expired separately from the authentication criteria the authentication itself is not compromised. Stuart Livings http://www.php.net/manual/en/features.cookies.php

« previous php.notes (#67243) next »