List Info

Thread: Re: Re: Session management without cookies?




Re: Re: Session management without cookies?
country flaguser name
United States
2007-03-21 09:34:16

>>&gt;>> "Damien" == Damien Carbery < daymobrew%40yahoo.com">daymobrewyahoo.com> writes:

Damien&gt; Only using the IP address would be very insecure, and useless if
Damien> people use a proxy or NAT router to access your site as you will see
Damien> one IP address for multiple people.

And dangerous if they're coming from AOL and other large nets... every
hit from an AOL user comes *from* a different address, even within the
same "page" hit. (Text from .3, image 1 from .5, image 2 from .7, etc.)

--
Randal L. Schwartz - Stonehenge Consulting Services, Inc. - +1 503 777 0095
<; merlyn%40stonehenge.com">merlynstonehenge.com> <URL:http://www.stonehenge.com/merlyn/>
Perl/Unix/security consulting, Technical writing, Comedy, etc. etc.
See PerlTraining.Stonehenge.com for onsite and open-enrollment Perl training!

__._,_.___
.

__,_._,___
[1]

about | contact  Other archives ( Real Estate discussion Medical topics )