in reply to Re: Re: cookies n variables
in thread cookies n variables
There is only one truely safe way to do this, and that is to maintain state with a cookie (or hidden params) (see previous post). The information stored server side is non-volatile, any information stored in a cookie is volatile and susceptible to tampering/attack/deletion et al.
Using a session NDV session id makes everything *that* much more safer. Of course there is safe and there is *safe*, and any solution chosen should represent the level of risk allowable for the project.
For example a site may manage content via a cookie, and default to a default page if the cookie is not found, however a bank may use any combination of challenge/response using a 3rd party token generator (ala secure_id)...
IMO it is *so* easy to produce a decent level of security with a NDV sess_id, and storing the information server side, why not do it? why put information into a volitile data source?
|
---|
Replies are listed 'Best First'. | |
---|---|
Re: Re: Re: Re: cookies n variables
by waswas-fng (Curate) on Nov 17, 2002 at 19:08 UTC | |
by Ryszard (Priest) on Nov 18, 2002 at 18:29 UTC | |
by waswas-fng (Curate) on Nov 18, 2002 at 22:44 UTC |