Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Encrypted passwords are useless!
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Encrypted passwords are useless!

 Post Reply Post Reply
Author
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Topic: Encrypted passwords are useless!
    Posted: 27 May 2003 at 11:16am

Well not useless!  Just suppose this however:

Im assuming passwords in cookies are encrypted so that if someone hacked your computer they could not gain access to it...

However, the hacker can simply copy+paste the cookie file over to their system and login to your account...

It prevents them seeing your passwords if you use the same one, but it does not prevent the from entering the system...

A solution?  How about storing an encrypted IP address in the cookie, and the cookie is only valid if the IP address matches.... However this wont really work for those 56k people....

Back to Top
MadDog View Drop Down
Mod Builder Group
Mod Builder Group
Avatar

Joined: 01 January 2002
Status: Offline
Points: 3008
Post Options Post Options   Thanks (0) Thanks(0)   Quote MadDog Quote  Post ReplyReply Direct Link To This Post Posted: 27 May 2003 at 11:29am
Just do it like this forum, make a new field called "User_code" and run the cookie off that.
Back to Top
michael View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 April 2002
Location: United States
Status: Offline
Points: 4670
Post Options Post Options   Thanks (0) Thanks(0)   Quote michael Quote  Post ReplyReply Direct Link To This Post Posted: 27 May 2003 at 12:05pm
And if security is such a huge concern, don't let your users store the password and have them enter it every time like most banking systems.
Back to Top
ljamal View Drop Down
Mod Builder Group
Mod Builder Group


Joined: 16 April 2003
Status: Offline
Points: 888
Post Options Post Options   Thanks (0) Thanks(0)   Quote ljamal Quote  Post ReplyReply Direct Link To This Post Posted: 27 May 2003 at 12:56pm
why would a hacker bother to copy and paste the cookie when they could just access the site from the computer then and there?

My advice is to never store sensitive information in a cookie. Generally I only store maybe first names in the cookie. Anything else would be information only useful if you had access to the database like IDs and date stamps.
Back to Top
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Posted: 27 May 2003 at 1:36pm
No i dont mean about a system im making myself, rather cookie passwords in general
Back to Top
the boss View Drop Down
Senior Member
Senior Member
Avatar

Joined: 19 January 2003
Location: Saudi Arabia
Status: Offline
Points: 1727
Post Options Post Options   Thanks (0) Thanks(0)   Quote the boss Quote  Post ReplyReply Direct Link To This Post Posted: 27 May 2003 at 11:40pm
copying cookie from one machine and pasting then in another rmachine doest works anytime for me!!!
Back to Top
Eftie View Drop Down
Groupie
Groupie


Joined: 17 March 2003
Location: Netherlands
Status: Offline
Points: 140
Post Options Post Options   Thanks (0) Thanks(0)   Quote Eftie Quote  Post ReplyReply Direct Link To This Post Posted: 28 May 2003 at 12:37am

<quote:>

How about storing an encrypted IP address in the cookie, and the cookie is only valid if the IP address matches....

</quote>

Maybe you have cable, but what about the thousands and thousands who use a dial-up connection and get every time another IP address?

Eftie
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.