Secure site login

Discussion in 'PHP' started by viron86, Nov 15, 2008.

  1. #1
    Previously I've always used a cookie to store a login, but which is better cookie or session?
     
    viron86, Nov 15, 2008 IP
  2. Shoro

    Shoro Peon

    Messages:
    143
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #2
    A session is pretty much a cookie with a bit of extra functionality. Unless you're storing the password in plaintext in the cookie or something, one isn't really more secure than the other.
     
    Shoro, Nov 15, 2008 IP
  3. Bind

    Bind Peon

    Messages:
    70
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #3
    session data is not viewable by a visitor

    cookie data is viewable by a visitor.

    as to security, its ok to store information in cookies but encrypt it using a unique key (with something like mCrypt), or hash it using $salt (md5($salt.$value);) if the value is for pure comparison purposes.

    The well-planned/coded visitor login authentication/validation will use both sessions and cookies.

    cookies generally allow for automated logins and visitor/site preferences storage without sacrificing security.
     
    Bind, Nov 15, 2008 IP
  4. shineDarkly

    shineDarkly Banned

    Messages:
    241
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #4
    the security does not depend on what function methodology you used, it depends on how carefully you planned your application and how good your knowledge of the PL is
     
    shineDarkly, Nov 16, 2008 IP