Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Tree View
#15
[quote name='Rainer' date='10 June 2010 - 06:04 PM' timestamp='1276185870' post='420']

Well, a general security rule is: "What you don't have (and store) cannot be stolen (that easy)".



A good website keeps membersettings in its own DB and sets up a cookie just for

the actual session ... eventually filled with data from its own DB. Yes, it means more work

for the website (since it cannot offload this stuf to the users side in that case) ... but it is

simply more secure.

[/quote]



Cookies impose no security risk per se.



They're only risky in an internet-cafe or stolen hardware scenario where your settings get "exposed" (and in the latter case cookies are the least problem). In an internet cafe you should use e.g. the "private mode" which is available in modern browsers. In this case cookies are deleted upon exiting the browser.



Even so the PZ cookies are harmless because here at PZ the worst thing that could happen would be spamming the forum with your account. This is different on sites with an auto-login where you can loose money or expose critical data - e.g. in web-shops or banks. A decent website with critical data will, of course, only allow temp-Cookies and not the persistent ones used for forums and such.
  


Messages In This Thread
Tree View - by Klaus - 06-04-2010, 08:35 AM
Tree View - by PuxaVida - 06-04-2010, 08:40 AM
Tree View - by mst - 06-04-2010, 08:52 AM
Tree View - by Sylvain - 06-04-2010, 10:03 AM
Tree View - by Rainer - 06-04-2010, 01:25 PM
Tree View - by toni-a - 06-04-2010, 03:56 PM
Tree View - by Rainer - 06-04-2010, 05:17 PM
Tree View - by Guest - 06-05-2010, 07:59 PM
Tree View - by Klaus - 06-09-2010, 09:40 AM
Tree View - by netrex - 06-09-2010, 08:20 PM
Tree View - by Guest - 06-10-2010, 02:32 PM
Tree View - by Guest - 06-10-2010, 03:51 PM
Tree View - by toni-a - 06-10-2010, 03:54 PM
Tree View - by Rainer - 06-10-2010, 04:04 PM
Tree View - by Klaus - 06-11-2010, 08:50 AM

Forum Jump:


Users browsing this thread:
1 Guest(s)