Beefy Boxes and Bandwidth Generously Provided by pair Networks
Perl Monk, Perl Meditation
 
PerlMonks  

(jptxs) Re: (jptxs) Re: Securing Passwords

by jptxs (Curate)
on Apr 02, 2001 at 19:43 UTC ( [id://69027]=note: print w/replies, xml ) Need Help??


in reply to Re: (jptxs) Re: Securing Passwords
in thread Securing Passwords

Maybe, maybe not. as tilly notes above, some DHCP servers refresh the address very frequently and it could be the case that the IP would change during one session even. If all they need is the cookie, then you may be fine as in the time that the whole process takes place the cookie is made and they have it and all is well. If the IP is validated in any way, it could change, and therefore invalidate the session. If it is not validated, you could argue that it's prone to spoofing if the cookie is intercepted in transit. The other problem is the case where the DHCP server changes the IP in the middle of the initial validation, then you're really screwed.

I worked with security products at a previous company, and, in every case, when they depended in any way on IPs, even the slightest, there were always problems with DHCP. it's a PITA for sure =)

"A man's maturity -- consists in having found again the seriousness one had as a child, at play." --Nietzsche

Log In?
Username:
Password:

What's my password?
Create A New User
Domain Nodelet?
Node Status?
node history
Node Type: note [id://69027]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this?Last hourOther CB clients
Other Users?
Others scrutinizing the Monastery: (10)
As of 2024-04-19 09:11 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    No recent polls found