dreamwest Posted June 5, 2009 Share Posted June 5, 2009 Ive been using cookies pretty heavily to acces certain areas of my site but i want to convert them to sessions instead. Thought i would ask here before i did anything - which is better. I know ppl can sometimes have thier browsers to not accept cookies, but is that the only drawback to using cookies? Quote Link to comment https://forums.phpfreaks.com/topic/161026-seesions-or-cookies/ Share on other sites More sharing options...
Wolphie Posted June 5, 2009 Share Posted June 5, 2009 Other websites could quite possibly access your cookies (which is bad if they contain user sensitive information). Facebook, for example have a few 'open' cookies where they're accessed by many websites you may visit. Quote Link to comment https://forums.phpfreaks.com/topic/161026-seesions-or-cookies/#findComment-849814 Share on other sites More sharing options...
GingerRobot Posted June 5, 2009 Share Posted June 5, 2009 I know ppl can sometimes have thier browsers to not accept cookies Session IDs are, by default, stored in a cookie anyway. Unless you start passing the session ID around in the URL, you're still relying on the user having cookie support enabled. And if you do pass it around in the URL, you increase the risk of session hijacking. Use cookies only to store things you want to store between visits to your site. I.e. if you want a remember me function then you'll be needing cookies. Otherwise, use sessions. Quote Link to comment https://forums.phpfreaks.com/topic/161026-seesions-or-cookies/#findComment-849818 Share on other sites More sharing options...
PFMaBiSmAd Posted June 5, 2009 Share Posted June 5, 2009 All cookies are domain specific. There is no such thing as an "open" cookie that is sent by the browser to all domains. Quote Link to comment https://forums.phpfreaks.com/topic/161026-seesions-or-cookies/#findComment-849819 Share on other sites More sharing options...
Daniel0 Posted June 5, 2009 Share Posted June 5, 2009 Sessions give you control over how to store the data. The only thing the user will then be responsible for storing is their own session identifier. Quote Link to comment https://forums.phpfreaks.com/topic/161026-seesions-or-cookies/#findComment-849820 Share on other sites More sharing options...
Wolphie Posted June 5, 2009 Share Posted June 5, 2009 All cookies are domain specific. There is no such thing as an "open" cookie that is sent by the browser to all domains. So then how does Facebook store cookies that enables other websites to identify your Facebook identity? Quote Link to comment https://forums.phpfreaks.com/topic/161026-seesions-or-cookies/#findComment-849825 Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.