Re: [php-gtk-webmaster] cvs: php-gtk-web / admin-logout.php
[email protected] (Andrei Zmievski) Sun, 9 Jul 2006 16:24:55 -0700
| Newsgroups | php.gtk.webmaster |
|---|---|
| Message-ID | <[email protected]> |
No, I haven't had time. What do you md5()? Do you have a "secret" that you append to the cookie before md5'ing? -Andrei On Jul 9, 2006, at 2:59 PM, Steph Fox wrote: > I already MD5'd it, didn't you look at the code? > >> Once again, signed cookies have nothing to do with SSL. They rely >> on hash algos like MD5 and SHA-1. >> -Andrei >> On Jul 9, 2006, at 2:37 PM, Steph Fox wrote: >>> Yeah I know about SSL. I just don't know if it's appropriate for >>> this. >>> >>>>> Whatever... it still needs to be a different cookie. >>>> Fine, so let's do that. >>>>> What do you mean by 'signed'? do we have a secure server setup? >>>> Signed cookies prevent tampering. You can read a bit about it here: >>>> http://www.hccfl.edu/pollock/Docs/PubKeyCrypto/ >>>> -Andrei >>>> __________ NOD32 1.1380 (20060125) Information __________ >>>> This message was checked by NOD32 antivirus system. >>>> http://www.eset.com >>>> >> __________ NOD32 1.1380 (20060125) Information __________ >> This message was checked by NOD32 antivirus system. >> http://www.eset.com >>