I think alot of the time everyone must weigh up the risks and advantages.
Everything CAN be hacked/cracked and or stolen.
everysystem designed and built has some kind of override built in, which if its found can be used by every hacker.
The best you can do is write your scripts as secure as possible.
unless the account handles or uses in some way the users money or anything like that only then would i worry too much about security of cookies, if itb is handling money then it should always be using a https "secure" (s******) connection.
You could if you so wish at least on first login, when the cookie is set use a secure connection which should minimise the risk of someone phishing the connection and stealing the cookies and there-fore impersonating that user to gain access..
I came really close to going into a mini-rant/explination of some of the flaws and that with https... BUT I RESISTED!! - i might have one on my blog tho...
dan
EDIT: i wasnt swearing btw... i jsut said snig ger 
__________________
Discounted Web Hosting With XDnet! >> Get 25% of hosting~ Promo: Webmaster-talk <<
Last edited by dansgalaxy; 09-13-2007 at 04:54 AM..
|