Gayner Posted November 15, 2009 Share Posted November 15, 2009 For user login/registration script Quote Link to comment https://forums.phpfreaks.com/topic/181595-is-_session-safest-way/ Share on other sites More sharing options...
YourNameHere Posted November 15, 2009 Share Posted November 15, 2009 I don't know a better way but I have seen discussions that say it is not. So I don't store any sensitive data in it without encrypting it first if I can. Quote Link to comment https://forums.phpfreaks.com/topic/181595-is-_session-safest-way/#findComment-957875 Share on other sites More sharing options...
Gayner Posted November 15, 2009 Author Share Posted November 15, 2009 I don't know a better way but I have seen discussions that say it is not. So I don't store any sensitive data in it without encrypting it first if I can. I encypte passwords using md5 and sacks or sock or w/e with it..g dood ? Quote Link to comment https://forums.phpfreaks.com/topic/181595-is-_session-safest-way/#findComment-957877 Share on other sites More sharing options...
Daniel0 Posted November 15, 2009 Share Posted November 15, 2009 It depends on how you use it. Quote Link to comment https://forums.phpfreaks.com/topic/181595-is-_session-safest-way/#findComment-957879 Share on other sites More sharing options...
YourNameHere Posted November 15, 2009 Share Posted November 15, 2009 I encypte passwords using md5... As do I... I also use sha1 Quote Link to comment https://forums.phpfreaks.com/topic/181595-is-_session-safest-way/#findComment-957880 Share on other sites More sharing options...
Gayner Posted November 15, 2009 Author Share Posted November 15, 2009 I encypte passwords using md5... As do I... I also use sha1 sha1 yea i use that but no1 needs protection unless u gonna be having a huge site that is very needy on money like gaia online or what not Quote Link to comment https://forums.phpfreaks.com/topic/181595-is-_session-safest-way/#findComment-957883 Share on other sites More sharing options...
mrMarcus Posted November 15, 2009 Share Posted November 15, 2009 but no1 needs protection unless u gonna be having a huge site that is very needy on money like gaia online or what not couldn't be further from the truth. security should always be a number one priority. for example, if you are storing users email addresses and passwords to login to your site, you might think that since you are not even on the radar in the terms of high-profile websites, but how many use the same email and password to register for a joe-blow site as they do to login to their actual email account. i bet the number is quite high. so, if buddy hacker gets into your site (and quite easily since security is not a concern for you), he now has a database full of email addresses and passwords (and while they may be hashed, he's also got ways of brute-forcing those). always take security seriously, no matter whether you're a "huge site" or not. Quote Link to comment https://forums.phpfreaks.com/topic/181595-is-_session-safest-way/#findComment-957941 Share on other sites More sharing options...
Daniel0 Posted November 15, 2009 Share Posted November 15, 2009 but no1 needs protection unless u gonna be having a huge site that is very needy on money like gaia online or what not Remind me not to sign up on any web site you created. Quote Link to comment https://forums.phpfreaks.com/topic/181595-is-_session-safest-way/#findComment-957942 Share on other sites More sharing options...
Gayner Posted November 15, 2009 Author Share Posted November 15, 2009 but no1 needs protection unless u gonna be having a huge site that is very needy on money like gaia online or what not Remind me not to sign up on any web site you created. You wouldn't anyway, and with that attitudei wouldn't want u, lol In any event i could tell u i used allprotection and u woulda've signed up I coulda tell u anything. How do u know . Quote Link to comment https://forums.phpfreaks.com/topic/181595-is-_session-safest-way/#findComment-958070 Share on other sites More sharing options...
sKunKbad Posted November 15, 2009 Share Posted November 15, 2009 Well, this thread is taking a funny direction. Quote Link to comment https://forums.phpfreaks.com/topic/181595-is-_session-safest-way/#findComment-958078 Share on other sites More sharing options...
mikesta707 Posted November 15, 2009 Share Posted November 15, 2009 sacks or sock or w/e with it..g dood ? perhaps you mean salt? Quote Link to comment https://forums.phpfreaks.com/topic/181595-is-_session-safest-way/#findComment-958082 Share on other sites More sharing options...
Irresistable Posted November 15, 2009 Share Posted November 15, 2009 Gayner.. you have some cheek on you. I understand how you think thaty if you using money in the buisness to have security. Though if you had a login, which tracked IP, location, etc.. upon registration, would you like hackers to find out that information and find you? I would think not. Not only is security about protecting the website, its about protecting yourself. If you wanted to use Session to create a very secure login, use IP detectors, so that if your IP isn't the same as the one on registration, then do not login. Though in terms of general security, it depends how it is used, as to whether it can be hacked into. Quote Link to comment https://forums.phpfreaks.com/topic/181595-is-_session-safest-way/#findComment-958131 Share on other sites More sharing options...
Gayner Posted November 15, 2009 Author Share Posted November 15, 2009 Gayner.. you have some cheek on you. I understand how you think thaty if you using money in the buisness to have security. Though if you had a login, which tracked IP, location, etc.. upon registration, would you like hackers to find out that information and find you? I would think not. Not only is security about protecting the website, its about protecting yourself. If you wanted to use Session to create a very secure login, use IP detectors, so that if your IP isn't the same as the one on registration, then do not login. Though in terms of general security, it depends how it is used, as to whether it can be hacked into. it's just a simple login registration form to let users have a big ego if there account is created , username and md5 with sha hash and a text for users to describe about them selves, lol nothing fancy Quote Link to comment https://forums.phpfreaks.com/topic/181595-is-_session-safest-way/#findComment-958136 Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.