in reply to RE: Encrypting or Hiding Certain Info in a URL
in thread Encrypting or Hiding Certain Info in a URL

If you plan implementing session id's
make sure that they are dynamic, and expire after say an hour.
Each time the person logs in their session id is good for about an hour, or less.
If the session id is static, it's just as good as a password.

  • Comment on RE: RE: Encrypting or Hiding Certain Info in a URL