Re: Package Proposal: Auth_HMAC
| From: | Martin Jansen | Date: | Thu, 24 Apr 2003 13:04:53 +0000 |
| Subject: | Re: Package Proposal: Auth_HMAC | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-15464@lists.php.net to get a copy of this message | ||
On Thu Apr 24, 2003 at 01:5226PM +0100, Davey wrote:
> OK, I've been working on a new login system for my CMS these last few
> weeks, and I now believe I have *the* strongest non-SSL login ever.
Brave words. But honestly, if I were you, I wouldn't proclaim them too
loud ;-).
> basically, *every* time the login form is generate, a random hash is
> generated (currently $hash = md5(uniqid(nt_rand(),1));), this is split
> into two halves and stored in $_SESSION.
May we see the code?
--
- Martin Martin Jansen
http://martinjansen.com/