Re: Re: cvs: pearweb /public_html login.php
| From: | Richard Heyes | Date: | Sun, 24 Nov 2002 12:07:45 +0000 |
| Subject: | Re: Re: cvs: pearweb /public_html login.php | ||
| References: | 1 2 3 4 5 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-11056@lists.php.net to get a copy of this message | ||
> > Been thinking about this. It would be even more secure if we could hash
with
> > two secrets, ie the password and some other secret. Problem is, with
pearweb
> > being open to the public this isn't really feasible, unless we use an
> > encoded function to do the hashing. I can supply the encoded function,
if we
> > can get the Optimizer installed on pearweb.
> >
> > How does this sound ?
>
> it would be much simpler to read a file stored outside of the web tree
> to get the server's secret, and that's less likely to break when someone
> upgrades php on that machine.
Kinda screws up portability though, since if it's not in cvs, it will have
to be retrieved separately by devs.
--
Richard Heyes