Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050

View Poll Results: Which is more secure?

Voters
8. You may not vote on this poll
  • Apache HTTP Auth

    1 12.50%
  • Session or Cookie login systems

    7 87.50%
Page 1 of 2 12 LastLast
Results 1 to 15 of 30

This is a discussion on HTTP_Auth or Sessions? in the Open Discussion & Chit-chat forum
I'm curious to see the responses I get to this here. Everybody seems to have thier own opinion. Which is more secure: Apache's http_authentication or ...

  1. #1
    JPC Guru
    Join Date
    Jan 2004
    Location
    I'm right behind you....
    Posts
    389

    HTTP_Auth or Sessions?

    I'm curious to see the responses I get to this here. Everybody seems to have thier own opinion.

    Which is more secure: Apache's http_authentication or a well-written login system of one's own design (using salt, multple md5, etc.)?

    Vote, discuss....

  2. #2
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Are you kidding?

    Basic Auth sucks!
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  3. #3
    Smo
    Smo is offline
    JPC Addict
    Join Date
    Nov 2002
    Location
    Finland
    Posts
    218
    I've always been under the impression that HTTP auth is more secure. but it's not as felxible as a custom made login system.

    Ofcourse I'm a n00b so my impressions are irrelevant

  4. #4
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Let's put it this way...

    Can you name one major e-commerce site that uses HTTP authentication?
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  5. #5
    Rob
    Rob is offline
    I am the one and only Rob's Avatar
    Join Date
    Nov 2005
    Location
    It varies
    Posts
    425
    Sessions are much much more secure than HTTP Auth

  6. #6
    Old Hillbilly Connie's Avatar
    Join Date
    Sep 2001
    Location
    Hills of Missouri
    Posts
    2,646
    Can you name one major e-commerce site that uses HTTP authentication?
    How would the average user know?

    I think akin to that. How would the average site owner know whether the authentication was
    was http or sessions?

    I could be wrong. I often am, but it appears to me the topic is drifting off from the original question.

    Forum Moderators - Jag Staff

    Spam Whackers Blog - Dedicated to fighting Spam and providing General SEO Tips
    Organize your Kitchen or purchase Kitchen Accessories at Condells
    Ihelpyou Forum - Dedicated to "Best Practices" SEO

  7. #7
    Loyal Client the_ancient's Avatar
    Join Date
    Feb 2004
    Posts
    3,386
    Quote Originally Posted by Connie View Post
    How would the average user know?

    I think akin to that. How would the average site owner know whether the authentication was
    was http or sessions?

    I could be wrong. I often am, but it appears to me the topic is drifting off from the original question.
    Aside from the Stupid Alert box that Basic Auth Uses vs the HTML Form most session based system use
    -------------------------
    the_ancient
    MP Technology Group

  8. #8
    Old Hillbilly Connie's Avatar
    Join Date
    Sep 2001
    Location
    Hills of Missouri
    Posts
    2,646
    Aside from the Stupid Alert box that Basic Auth Uses vs the HTML Form most session based system use
    Never saw a stupid alert box that I know of on any site. Not sure what you are referring to?

    Forum Moderators - Jag Staff

    Spam Whackers Blog - Dedicated to fighting Spam and providing General SEO Tips
    Organize your Kitchen or purchase Kitchen Accessories at Condells
    Ihelpyou Forum - Dedicated to "Best Practices" SEO

  9. #9
    JPC Guru
    Join Date
    Jan 2004
    Location
    I'm right behind you....
    Posts
    389
    Connie, when you log into your cPanel, you get the stupid alert box. That's http auth. When you log into your Jag client section, you use an html form. That's session based.

    Hmm... could I get some specific reasons as to why one is better than the other? What makes sessions better? Other than the ability to customize, I mean. That's obvious

  10. #10
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by Connie View Post
    How would the average user know?
    Duh!

    Basic Auth is supposed to include all kinds of warniings about passing passwords in the the clear, and so forth, and so on...

    n/m

    You've probably (summarily) told MSIE not to send you these warning messages in the future...

    [Removed text]
    Last edited by Connie; 02-11-2007 at 05:11 PM. Reason: No need for name calling
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  11. #11
    Loyal Client the_ancient's Avatar
    Join Date
    Feb 2004
    Posts
    3,386
    Quote Originally Posted by Vin DSL View Post
    Gawd! I'm surrounded by [removed]...
    only if your surrounded my mirrors
    Last edited by Connie; 02-11-2007 at 05:17 PM. Reason: see original post
    -------------------------
    the_ancient
    MP Technology Group

  12. #12
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by the_ancient View Post
    only if your surrounded my mirrors
    Good come-back!

    What's wrong with your Shift-key?
    Last edited by Ron; 02-11-2007 at 07:36 PM.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  13. #13
    Old Hillbilly Connie's Avatar
    Join Date
    Sep 2001
    Location
    Hills of Missouri
    Posts
    2,646
    How about no more name calling?

    Every question, and every response should be respected by other members of the forum IMHO.

    Just because someone is not at your particular skill level does not make them less intelligent.

    Forum Moderators - Jag Staff

    Spam Whackers Blog - Dedicated to fighting Spam and providing General SEO Tips
    Organize your Kitchen or purchase Kitchen Accessories at Condells
    Ihelpyou Forum - Dedicated to "Best Practices" SEO

  14. #14
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by Connie View Post
    Every question, and every response should be respected by other members of the forum IMHO.
    IMHO, you should turn your warnings back on, if you plan to use Basic Auth...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  15. #15
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by Galen View Post
    I'm curious to see the responses I get to this here. Everybody seems to have thier own opinion... Vote, discuss...
    Okay, bro!

    I responded, voiced my opinion, voted, disgust [pun intended], and got censored...

    Good luck!

    See ya in the next thread...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •