Re: Re: cvs: pearweb /public_html login.php
| From: | Richard Heyes | Date: | Sat, 23 Nov 2002 12:08:32 +0000 |
| Subject: | Re: Re: cvs: pearweb /public_html login.php | ||
| References: | 1 2 3 | Groups: | php.pear.cvs |
| Request: | Send a blank email to pear-cvs+get-7544@lists.php.net to get a copy of this message | ||
> > one way to make something a little less vulnerable would be to have a
> > cookie with the time, the user id, and a hash of those values with a
> > secret value (possibly the user's password). don't accept cookies that
> > are past some age, but issue a new one on every request (or only some
> > requests) with an updated timestamp and hash.
Been thinking about this. It would be even more secure if we could hash with
two secrets, ie the password and some other secret. Problem is, with pearweb
being open to the public this isn't really feasible, unless we use an
encoded function to do the hashing. I can supply the encoded function, if we
can get the Optimizer installed on pearweb.
How does this sound ?
--
Richard Heyes