Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #3684
| From | "sl@exabyte" <sb5309@hotmail.com> |
|---|---|
| Newsgroups | comp.lang.php |
| Subject | Re: session cookie: client side |
| Date | 2011-11-04 22:21 +0800 |
| Organization | albasani.net |
| Message-ID | <j90sdg$qle$1@news.albasani.net> (permalink) |
| References | <j8tlr0$idi$1@news.albasani.net> <4147316.976.1320323017283.JavaMail.geo-discussion-forums@yqnv12> <j8vvsn$ub6$1@news.albasani.net> <j90jsq$550$1@dont-email.me> |
> The cookie does not identify the user - it is just the session id. What > the server does with it is something else. > > In general, the session id does identify the computer from which the > cookie is being sent because the session id is a rather long > pseudo-random alphanumeric value. Yes it's possible for someone else > to intercept and read the session id, but in general it's unlikely. > > The real question is - what is the problem you are trying to resolve? > If the data are that sensitive, you should be using a secure protocol > for everything. If the data aren't sensitive enough to require a > secure protocol, why do you think the cookie is? I think I am missing something. By the term 'secure protocol', ie SSL, implies that HTTPS be used, rather than HTTP, isn't it ? Sorry if it is a stupid question. Anyway I shall google for SSL and HTTPS.
Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
session cookie: client side "sl@exabyte" <sb5309@hotmail.com> - 2011-11-03 17:10 +0800
Re: session cookie: client side Balazs Nadasdi <yitsushi@gmail.com> - 2011-11-03 05:23 -0700
Re: session cookie: client side "sl@exabyte" <ecp_gen@my-rialto.com> - 2011-11-04 14:14 +0800
Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 07:55 -0400
Re: session cookie: client side "sl@exabyte" <sb5309@hotmail.com> - 2011-11-04 22:21 +0800
Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 14:40 -0400
Re: session cookie: client side Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-04 15:53 +0000
Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 14:41 -0400
Re: session cookie: client side Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-04 15:52 +0000
csiph-web