Re: Package Proposal: Auth_HMAC
| From: | Davey | Date: | Thu, 24 Apr 2003 13:14:19 +0000 |
| Subject: | Re: Package Proposal: Auth_HMAC | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-15465@lists.php.net to get a copy of this message | ||
Well, brave words as they may be, I'm hoping it'll get a) some rigourous testing and b) proven
I have had the code reviewed by serveral people I (and many others) believe to be well endowed with PHP knowledge, and all have said the code looks decent, so we'll see :D
As I said, I will release the code soon, I have also noticed the Crypt_HMAC package, so I'll use that if anything pre-existing in PEAR (if its compatible :)
- Davey
Martin Jansen wrote:
On Thu Apr 24, 2003 at 01:5226PM +0100, Davey wrote:OK, I've been working on a new login system for my CMS these last few weeks, and I now believe I have *the* strongest non-SSL login ever.Brave words. But honestly, if I were you, I wouldn't proclaim them too loud ;-).basically, *every* time the login form is generate, a random hash is generated (currently $hash = md5(uniqid(nt_rand(),1));), this is split into two halves and stored in $_SESSION.May we see the code?