Re: [php-gtk-webmaster] cvs: php-gtk-web / admin-logout.php

[email protected] (Andrei Zmievski) Sun, 9 Jul 2006 16:24:55 -0700
Newsgroups php.gtk.webmaster
Message-ID <[email protected]>
No, I haven't had time. What do you md5()? Do you have a "secret"  
that you append to the cookie before md5'ing?

-Andrei


On Jul 9, 2006, at 2:59 PM, Steph Fox wrote:

> I already MD5'd it, didn't you look at the code?
>
>> Once again, signed cookies have nothing to do with SSL. They rely  
>> on  hash algos like MD5 and SHA-1.
>> -Andrei
>> On Jul 9, 2006, at 2:37 PM, Steph Fox wrote:
>>> Yeah I know about SSL. I just don't know if it's appropriate for  
>>> this.
>>>
>>>>> Whatever... it still needs to be a different cookie.
>>>> Fine, so let's do that.
>>>>> What do you mean by 'signed'? do we have a secure server setup?
>>>> Signed cookies prevent tampering. You can read a bit about it here:
>>>> http://www.hccfl.edu/pollock/Docs/PubKeyCrypto/
>>>> -Andrei
>>>> __________ NOD32 1.1380 (20060125) Information __________
>>>> This message was checked by NOD32 antivirus system.
>>>> http://www.eset.com
>>>>
>> __________ NOD32 1.1380 (20060125) Information __________
>> This message was checked by NOD32 antivirus system.
>> http://www.eset.com
>>