I'm curious to see the responses I get to this here. Everybody seems to have thier own opinion.
Which is more secure: Apache's http_authentication or a well-written login system of one's own design (using salt, multple md5, etc.)?
Vote, discuss....
This is a discussion on HTTP_Auth or Sessions? in the Open Discussion & Chit-chat forum
I'm curious to see the responses I get to this here. Everybody seems to have thier own opinion.
Which is more secure: Apache's http_authentication or ...
I'm curious to see the responses I get to this here. Everybody seems to have thier own opinion.
Which is more secure: Apache's http_authentication or a well-written login system of one's own design (using salt, multple md5, etc.)?
Vote, discuss....
Are you kidding?
Basic Auth sucks!![]()
DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.
I've always been under the impression that HTTP auth is more secure. but it's not as felxible as a custom made login system.
Ofcourse I'm a n00b so my impressions are irrelevant![]()
Let's put it this way...
Can you name one major e-commerce site that uses HTTP authentication?![]()
DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.
Sessions are much much more secure than HTTP Auth
How would the average user know?Can you name one major e-commerce site that uses HTTP authentication?
I think akin to that. How would the average site owner know whether the authentication was
was http or sessions?
I could be wrong. I often am, but it appears to me the topic is drifting off from the original question.
Forum Moderators - Jag Staff
Spam Whackers Blog - Dedicated to fighting Spam and providing General SEO Tips
Organize your Kitchen or purchase Kitchen Accessories at Condells
Ihelpyou Forum - Dedicated to "Best Practices" SEO
Never saw a stupid alert box that I know of on any site. Not sure what you are referring to?Aside from the Stupid Alert box that Basic Auth Uses vs the HTML Form most session based system use
Forum Moderators - Jag Staff
Spam Whackers Blog - Dedicated to fighting Spam and providing General SEO Tips
Organize your Kitchen or purchase Kitchen Accessories at Condells
Ihelpyou Forum - Dedicated to "Best Practices" SEO
Connie, when you log into your cPanel, you get the stupid alert box. That's http auth. When you log into your Jag client section, you use an html form. That's session based.
Hmm... could I get some specific reasons as to why one is better than the other? What makes sessions better? Other than the ability to customize, I mean. That's obvious![]()
Last edited by Connie; 02-11-2007 at 05:11 PM. Reason: No need for name calling
DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.
Last edited by Connie; 02-11-2007 at 05:17 PM. Reason: see original post
Last edited by Ron; 02-11-2007 at 07:36 PM.
DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.
How about no more name calling?
Every question, and every response should be respected by other members of the forum IMHO.
Just because someone is not at your particular skill level does not make them less intelligent.
Forum Moderators - Jag Staff
Spam Whackers Blog - Dedicated to fighting Spam and providing General SEO Tips
Organize your Kitchen or purchase Kitchen Accessories at Condells
Ihelpyou Forum - Dedicated to "Best Practices" SEO
DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.
DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.
Copyright © 2011 JaguarPC.com
Bookmarks