Latest Episode
Share This Page

Go Back   Keith and The Girl Forums Keith and The Girl Forums Talk Shite

Talk Shite General discussion

Reply
 
Thread Tools Display Modes
Old 07-16-2009, 12:08 AM   #61 (permalink)
Senior Member
 
hayroob's Avatar
 
Join Date: Mar 2008
Location: Detroitish
Posts: 1,386
So this is what I've been working on instead of posting here for the last few days:
Secure Persistent Login With Very Little SSL Part 1 | Get It Down On Paper
and
Secure Persistent Login With Very Little SSL Part 2 | Get It Down On Paper

If you're into web programming/security let me know what you think.

Last edited by hayroob; 07-16-2009 at 12:43 PM.
(Offline)   Reply With Quote
Old 07-16-2009, 07:16 AM   #62 (permalink)
Senior Member
 
Subsonix's Avatar
 
Join Date: Aug 2006
Location: Melbourne, Australia
Posts: 462
Quote:
Originally Posted by hayroob View Post
So this is what I've been working on instead of posting here for the last few days:
Secure Persistent Login With Very Little SSL Part 1 | Get It Down On Paper
and
Secure Persistent Login With Very Little SSL Part 2 | Get It Down On Paper

If you're into web programming/security let me know what you think.
I DO NOT KAY YOUR BLOG.

Please add pictures and funneh to explain.

KTHNKBAI.
(Offline)   Reply With Quote
Old 07-16-2009, 09:41 AM   #63 (permalink)
Senior Member
 
Join Date: Nov 2005
Location: Tampa, FL
Posts: 254
I see an issue the cookie has to be valid for both the http side and the https , otherwise when you switch to http after logging in you will get stuck in a login loop. One way to accomplish this is to have the cookie set via http point to the https id using a secure identifier (ie salt etc). The main issue is the cookie for http will be passed in clear text over the wire so whatever info you put into it cannot be used to login directly to the site if someone yanked the cookie. Also, you should look into separating your HTML and php using something like smarty. (Just a suggestion makes the code look clean)
__________________
(Offline)   Reply With Quote
Old 07-16-2009, 11:36 AM   #64 (permalink)
Senior Member
 
hayroob's Avatar
 
Join Date: Mar 2008
Location: Detroitish
Posts: 1,386
Quote:
Originally Posted by colk View Post
I see an issue the cookie has to be valid for both the http side and the https , otherwise when you switch to http after logging in you will get stuck in a login loop. One way to accomplish this is to have the cookie set via http point to the https id using a secure identifier (ie salt etc). The main issue is the cookie for http will be passed in clear text over the wire so whatever info you put into it cannot be used to login directly to the site if someone yanked the cookie. Also, you should look into separating your HTML and php using something like smarty. (Just a suggestion makes the code look clean)
I'll look into the smarty thing, I do enjoy clean code.

I think you misunderstood, there is a php session cookie that works over http and https that is responsible for actually being logged in, the https hash cookie (snickers to himself) is only responsible for reauthentication which is done over https.

If there's confusing or poorly explained language in my article I would love feedback to make it more clear.

EDIT: I have added a link to my live implementation in part 1

Last edited by hayroob; 07-16-2009 at 11:47 AM.
(Offline)   Reply With Quote
Old 07-16-2009, 12:43 PM   #65 (permalink)
Senior Member
 
hayroob's Avatar
 
Join Date: Mar 2008
Location: Detroitish
Posts: 1,386
I submitted my code to a site that talks about this stuff, if people could give me a vote it would really help drive traffic to my blog.

Hacker News | Secure Persistent Login With Very Little SSL Redux

Last edited by hayroob; 07-16-2009 at 01:18 PM.
(Offline)   Reply With Quote
Old 07-16-2009, 01:19 PM   #66 (permalink)
Senior Member
 
hayroob's Avatar
 
Join Date: Mar 2008
Location: Detroitish
Posts: 1,386
Just as an FYI you have to click the little arrow next to the post to vote, it's dumb and it took me a minute to realize so I thought I'd post it.
(Offline)   Reply With Quote
Old 07-16-2009, 02:27 PM   #67 (permalink)
Junior Member
 
Bri Mad's Avatar
 
Join Date: Jan 2009
Posts: 6
Thanks!

Wow. Streaming works great, and I can see the upcoming show time with one button press.

Thanks for adding me, and for all the work, Hayroob!

B
(Offline)   Reply With Quote
Old 07-16-2009, 02:30 PM   #68 (permalink)
Senior Member
 
hayroob's Avatar
 
Join Date: Mar 2008
Location: Detroitish
Posts: 1,386
Quote:
Originally Posted by Bri Mad View Post
Wow. Streaming works great, and I can see the upcoming show time with one button press.

Thanks for adding me, and for all the work, Hayroob!

B
I'll tell you what I tell everybody, I accept gratitude in the forms of nice sayings, donations (note the link in my sig) and pictures of boobs (girls boobs, no picture of dicks, looking at you newsy)
(Offline)   Reply With Quote
Old 07-16-2009, 02:41 PM   #69 (permalink)
Senior Member
 
outlaw's Avatar
 
Join Date: Jan 2006
Location: ATL
Posts: 179
Quote:
Originally Posted by hayroob View Post
Just as an FYI you have to click the little arrow next to the post to vote, it's dumb and it took me a minute to realize so I thought I'd post it.
Wow, you weren't kidding. Even after reading your post, it took me a minute to find that arrow. Talk about bad UI design, that site is horrible. Oh well, my vote has been cast. Good luck.
(Offline)   Reply With Quote
Old 07-16-2009, 02:48 PM   #70 (permalink)
Senior Member
 
hayroob's Avatar
 
Join Date: Mar 2008
Location: Detroitish
Posts: 1,386
Quote:
Originally Posted by outlaw View Post
Wow, you weren't kidding. Even after reading your post, it took me a minute to find that arrow. Talk about bad UI design, that site is horrible. Oh well, my vote has been cast. Good luck.
Thanks for the vote, and yes the UI on that site is shittastic, I found it by clicking on literally everything until something happened. This is what happens when engineers build websites, but don't talk to designers. It never crashes and the performance is great, but only if you can actually decrypt their nonsense layout.
(Offline)   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


All times are GMT -5. The time now is 04:24 AM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
Keith and The Girl
iPhone news and app directory