Re: security of sessions

From: chris (someone_at_here.com)
Date: 10/28/04


Date: Fri, 29 Oct 2004 05:29:59 +0800

yeh thats what i thought

thanks

"Tony Marston" <tony@NOSPAM.demon.co.uk> wrote in message
news:clrma8$jcg$1$8302bc10@news.demon.co.uk...
> Usernames and passwords should really be stored in a database, with the
> password encrypted. You do NOT want such information sitting around in a
> file that every Tom, *** and Harry can read.
>
> --
> Tony Marston
>
> http://www.tonymarston.net
>
>
>
> "chris" <someone@here.com> wrote in message
> news:41814e5b$1@funnel.arach.net.au...
>> im just starting to learn how sessions work and how to use them
>>
>> my question is if im geting a username and password from a visitor is it
>> secure to store that information in a session variable or is it better to
>> store that information in a database and retrieve it when needed or
>> wouldnt it make any difference??
>>
>> thanks
>> chris
>>
>
>


Quantcast