Re: Package Proposal: Auth_HMAC

From: Date: Thu, 24 Apr 2003 13:14:19 +0000
Subject: Re: Package Proposal: Auth_HMAC
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-15465@lists.php.net to get a copy of this message
Well, brave words as they may be, I'm hoping it'll get a) some rigourous testing and b) proven I have had the code reviewed by serveral people I (and many others) believe to be well endowed with PHP knowledge, and all have said the code looks decent, so we'll see :D As I said, I will release the code soon, I have also noticed the Crypt_HMAC package, so I'll use that if anything pre-existing in PEAR (if its compatible :) - Davey Martin Jansen wrote:
On Thu Apr 24, 2003 at 01:5226PM +0100, Davey wrote:
OK, I've been working on a new login system for my CMS these last few weeks, and I now believe I have *the* strongest non-SSL login ever.
Brave words. But honestly, if I were you, I wouldn't proclaim them too loud ;-).
basically, *every* time the login form is generate, a random hash is generated (currently $hash = md5(uniqid(nt_rand(),1));), this is split into two halves and stored in $_SESSION.
May we see the code?


« previous php.pear.dev (#15465) next »