in reply to Encrypt web form values
If you do not want the data to be known, then just don't send the data. Instead send a cookie and keep the data on your system. The data in the cookie (which can be as simple as a UUID) will be the key to your cookie-vault where the webserver can retrieve it.
And if you want to avoid eavesdroppers, use a secure protocol such as HTTPS, so third parties cannot even intercept the cookie's content and use it in a replay-attack.
Oh yes, and of course use only session cookies and expire them in any case after a short while of no connections.
CountZero
A program should be light and agile, its subroutines connected like a string of pearls. The spirit and intent of the program should be retained throughout. There should be neither too little or too much, neither needless loops nor useless variables, neither lack of structure nor overwhelming rigidity." - The Tao of Programming, 4.1 - Geoffrey James
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Encrypt web form values
by Anonymous Monk on Dec 06, 2008 at 01:36 UTC | |
by fmerges (Chaplain) on Dec 06, 2008 at 06:56 UTC | |
by Anonymous Monk on Dec 06, 2008 at 12:44 UTC | |
by fmerges (Chaplain) on Dec 06, 2008 at 15:12 UTC | |
by Anonymous Monk on Dec 07, 2008 at 02:59 UTC |