Jump to content

security about cookie login


greatstar00

Recommended Posts

I read a forum, it said, cookie should be used to store none sensitive data

and they said, for a log in form, we shouldnt even store encrypted password, and encrypted username.

They said, only to store session.

my question is

how can i let the user log in automatically like 10 days later, if he choose remember me, which with cookie set at his computer

because we shouldnt hold the cookie that long. or we can hold it that long, without server performance slow down alot? (imagine i have 10000+ users)

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.