in reply to Cookies & Encryption
You can't "decrypt" the Digest::MD5 encryption. The strings produced are not necessarily unique, meaning that if someone comes across the encrypted data they cannot turn it back into the original. The best use for this is too encrypt the key to a unique user in a server side database, and check that the encrypted cookie matches the encrypted key on the server, then give the submitting user access to the associated info. merlyn goes through the whole technique very thoroughly (and with many precautions and tricks that I haven't given you) in his Web Technique column. Check out http://web.stonehenge.com/merlyn/WebTechniques/col32.html
Cheers,
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Cookies & Encryption
by chiller (Scribe) on Apr 14, 2002 at 22:35 UTC | |
|
Re: Re: Cookies & Encryption
by Ryszard (Priest) on Apr 15, 2002 at 02:12 UTC | |
by ehdonhon (Curate) on Apr 15, 2002 at 03:31 UTC | |
by Ryszard (Priest) on Apr 15, 2002 at 03:55 UTC | |
by kappa (Chaplain) on Apr 16, 2002 at 14:28 UTC |