Re: security of sessions

From: Tony Marston (tony_at_NOSPAM.demon.co.uk)
Date: 10/28/04


Date: Thu, 28 Oct 2004 21:54:32 +0100

Usernames and passwords should really be stored in a database, with the
password encrypted. You do NOT want such information sitting around in a
file that every Tom, Dick and Harry can read.

-- 
Tony Marston
http://www.tonymarston.net
"chris" <someone@here.com> wrote in message 
news:41814e5b$1@funnel.arach.net.au...
> im just starting to learn how sessions work and how to use them
>
> my question is if im geting a username and password from a visitor is it 
> secure to store that information in a session variable or is it better to 
> store that information in a database and retrieve it when needed or 
> wouldnt it make any difference??
>
> thanks
> chris
> 


Relevant Pages

  • Re: security of sessions
    ... Usernames and passwords should really be stored in a database, ... > im just starting to learn how sessions work and how to use them ... > secure to store that information in a session variable or is it better to ...
    (comp.lang.php)
  • Re: security of sessions
    ... > Usernames and passwords should really be stored in a database, ... >> im just starting to learn how sessions work and how to use them ... >> secure to store that information in a session variable or is it better to ...
    (comp.lang.php)
  • Re: security of sessions
    ... > Usernames and passwords should really be stored in a database, ... >> im just starting to learn how sessions work and how to use them ... >> secure to store that information in a session variable or is it better to ...
    (alt.php)
  • Re: public and private mailboxes randomly dismounting
    ... When posting logs an important piece is the Event ID and Source. ... Information Store First Storage Group: An attempt to move the file ... An error occurred while writing to the database log file of storage group ...
    (microsoft.public.windows.server.sbs)
  • Re: cant mount information store
    ... I then reinstalled exchange and then installed exchange 2003 ... Information Store First Storage Group: Database recovery failed ... Microsoft Exchange Information Store. ...
    (microsoft.public.windows.server.sbs)