Re: Re[2]: [PEAR-DEV] We need another Auth

From: Date: Mon, 10 Jun 2002 12:47:06 +0000
Subject: Re: Re[2]: [PEAR-DEV] We need another Auth
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-6867@lists.php.net to get a copy of this message
On Mon, 10 Jun 2002 13:56:08 +0200 Bertrand Mansion <bmansion@mamasam.com> wrote: > True, you can store something telling you the user is authenticated in a > cookie but this is very risky. Or you can pass this value along your urls > (even more risky). There is not other way to handle "secure" authentification around a non secure protocol. As far you need a near perfect secure authentification, ssl or whatever secured protocols have to be used. > At the moment, I can't think of a better way to handle authentication than > sessions. Even if someone could hijack your session id (because it is stored > in your cookie or your url) and get authenticated this way. It can be done > by using some javascript code. For instance, I am the admin of a job offers > site. People can post new offers on my site by using a form. In the job > description field, someone write some javascript to get the cookie value and > send this value to some other site which is just waiting for it. When me, > the admin, I am browsing the new offers, the javascript launches and the > other site knows my session id and can hijack my authenticated session. Here you get confusion between the authentification system and the form validation. Basic validation features is to remove scripts from any forms post if you will not allow them. > You could even imagine some viruses which would go through your cookie files > and send the value it finds somewhere on the internet (a newsgroup). > OK, this is fantasy but it still is possible, especially with windows. A web server cannot make the client OS more secure, but can prevent wrong data or spoofing. I do not know if a ssl connection is actually suitable for a large public site. I hope most of users supports ssl now. Yahoo, for example, uses ssl for the privat section. It's clear there is a need for an advanced authenfication system. Auth has not been created to match this goal, and this point has been discussed last week. Note that may be very difficult to make a generic authentification AND permissions system, I rembember someone told us about past discussions about this kind of modules, is the archive available somewhere ? pa

« previous php.pear.dev (#6867) next »