Re: Re: cvs: pearweb /public_html login.php
| From: | Jim Winstead | Date: | Sat, 23 Nov 2002 18:27:30 +0000 |
| Subject: | Re: Re: cvs: pearweb /public_html login.php | ||
| References: | 1 2 3 4 | Groups: | php.pear.cvs |
| Request: | Send a blank email to pear-cvs+get-7546@lists.php.net to get a copy of this message | ||
On Sat, Nov 23, 2002 at 12:08:32PM -0000, Richard Heyes wrote:
> > > one way to make something a little less vulnerable would be to have a
> > > cookie with the time, the user id, and a hash of those values with a
> > > secret value (possibly the user's password). don't accept cookies that
> > > are past some age, but issue a new one on every request (or only some
> > > requests) with an updated timestamp and hash.
>
> Been thinking about this. It would be even more secure if we could hash with
> two secrets, ie the password and some other secret. Problem is, with pearweb
> being open to the public this isn't really feasible, unless we use an
> encoded function to do the hashing. I can supply the encoded function, if we
> can get the Optimizer installed on pearweb.
>
> How does this sound ?
it would be much simpler to read a file stored outside of the web tree
to get the server's secret, and that's less likely to break when someone
upgrades php on that machine.
jim