DCHP - IP stays the same for that session doesn't it? That's all I need.
Mobile users - the application I use it for is not designed to use mobile phones.
AFAIK, AOL is our only problem (users' requests get sent through multiple proxy servers?!?! I'm not even sure about that issue even existing - I read it somewhere, but our clients don't use AOL, so again, not an issue), It's only used to check that this session is being run from the same IP that logged in.
"IP is not a reliable method of identification in any scheme"
I agree. What I mean is that the IP is not being used to identify the user, the password does that. I only use the IP to ensure that all future requests are made using a cookie that is useless if stolen and used by another user.
But then, like I said, this is what I use. Different circumstances require different approaches. This was the best I could think of for my particular task :)
later
cLive ;-)
In reply to Re: (jptxs) Re: Securing Passwords
by cLive ;-)
in thread Securing Passwords
by Dr. Mu
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |