Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #3689

Re: session cookie: client side

From Jerry Stuckle <jstucklex@attglobal.net>
Newsgroups comp.lang.php
Subject Re: session cookie: client side
Date 2011-11-04 14:40 -0400
Organization A noiseless patient Spider
Message-ID <j91bie$ah6$1@dont-email.me> (permalink)
References <j8tlr0$idi$1@news.albasani.net> <4147316.976.1320323017283.JavaMail.geo-discussion-forums@yqnv12> <j8vvsn$ub6$1@news.albasani.net> <j90jsq$550$1@dont-email.me> <j90sdg$qle$1@news.albasani.net>

Show all headers | View raw


On 11/4/2011 10:21 AM, sl@exabyte wrote:
>> The cookie does not identify the user - it is just the session id. What
>> the server does with it is something else.
>>
>> In general, the session id does identify the computer from which the
>> cookie is being sent because the session id is a rather long
>> pseudo-random alphanumeric value.  Yes it's possible for someone else
>> to intercept and read the session id, but in general it's unlikely.
>>
>> The real question is - what is the problem you are trying to resolve?
>> If the data are that sensitive, you should be using a secure protocol
>> for everything.  If the data aren't sensitive enough to require a
>> secure protocol, why do you think the cookie is?
>
> I think I am missing something. By the term 'secure protocol', ie SSL,
> implies that HTTPS be used, rather than HTTP, isn't it ?
>
> Sorry if it is a stupid question. Anyway I shall google for SSL and HTTPS.
>
>

A secure protocol is one in which the content is encrypted between the 
two systems.  For web pages, it would typically be https.  Command line 
prompts would generally be ssl.  There are others also, i.e. for ftp and 
other protocols.

But you still haven't answered the question - what are you trying to 
accomplish?  What is sensitive enough that it requires a secure protocol?

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

session cookie: client side "sl@exabyte" <sb5309@hotmail.com> - 2011-11-03 17:10 +0800
  Re: session cookie: client side Balazs Nadasdi <yitsushi@gmail.com> - 2011-11-03 05:23 -0700
    Re: session cookie: client side "sl@exabyte" <ecp_gen@my-rialto.com> - 2011-11-04 14:14 +0800
      Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 07:55 -0400
        Re: session cookie: client side "sl@exabyte" <sb5309@hotmail.com> - 2011-11-04 22:21 +0800
          Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 14:40 -0400
        Re: session cookie: client side Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-04 15:53 +0000
          Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 14:41 -0400
      Re: session cookie: client side Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-04 15:52 +0000

csiph-web