Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 1 of 2 12 LastLast
Results 1 to 10 of 16
  1. #1
    Join Date
    Jan 2008
    Posts
    287
    Tokens
    0

    Default User authentication

    Just wondering how the majority of HxF uses sessions.

    Do you:

    1. Use cookies.
    2. Use $_SESSION
    3. Another method? Explain.


  2. #2
    Join Date
    Mar 2007
    Posts
    106
    Tokens
    0

    Default

    Other(cause i don't know the full method)
    I use vbulletins login, i basically use my own script to encrypt the passwords and send it off to the vbulletin login that sets cookies for three different sites.

    The Forum
    The Main Site
    And the radio
    all are hosted on the same server just different domains. This enables every user to only have to login once.

    Bryce

  3. #3
    Join Date
    Jan 2007
    Location
    Canada eh?
    Posts
    766
    Tokens
    75

    Default

    I use sessions ($_SESSION). My main reasons for this are as follows;

    a) They aren't stored in the browser and therefore it is more difficult for the user to interfere/mess around with them.

    b) They are easier to set, modify, and unset/delete.

    c) Sessions work on a per-site/per-server basis and therefore if a user has a session set by your site and then they go visit joe's website, joe's website won't be able to access or view the sessions set by your site.

    d) Since sessions are stored on the server and not in the browser there's less back and forth between the two which [to some extent] makes sessions more secure.

    e) Sessions work even if cookies have been disabled in the users browser.

    f) I have just always used sessions and so I stick with what I know best

  4. #4
    Join Date
    Jul 2005
    Location
    Belgium
    Posts
    2,492
    Tokens
    147

    Latest Awards:

    Default

    $_sessions here, been using it on all my systems, love it

  5. #5

    Default

    I used to use cookies a lot because i don't see why everyone says they're so insecure, if you use them properly they're perfectly secure. But lately I've been using sessions they're just easier to work with i guess..

  6. #6
    Join Date
    May 2006
    Posts
    1,797
    Tokens
    0

    Latest Awards:

    Default

    I use both sessions and cookies.

    Depends if i want the user to still be logged in next time they visit the page.
    Coming and going...
    Highers are getting the better of me

  7. #7
    Join Date
    Jan 2008
    Posts
    287
    Tokens
    0

    Default

    Quote Originally Posted by Jme View Post
    I used to use cookies a lot because i don't see why everyone says they're so insecure, if you use them properly they're perfectly secure. But lately I've been using sessions they're just easier to work with i guess..
    Well to be honest, most users on HxF are not experienced enough to make cookies secure, hence why they use sessions.

  8. #8
    Join Date
    Feb 2006
    Location
    Ontario Canada
    Posts
    4,587
    Tokens
    0

    Latest Awards:

    Default

    session's
    Running a game security is the one of the main concerns

    .:.:#14:.:. .:.: Impossible Is Nothing :.:. .:.: 845 Rep:.:.
    .:.: Stand up for what is right, even if you stand alone:.:.


  9. #9
    Join Date
    Jan 2008
    Posts
    287
    Tokens
    0

    Default

    Quote Originally Posted by Colin-Roberts View Post
    session's
    Running a game security is the one of the main concerns
    True, but just because you use sessions does not ensure security, there are ways to use them.. and ways to not.

  10. #10
    Join Date
    Jan 2007
    Location
    Canada eh?
    Posts
    766
    Tokens
    75

    Default

    Quote Originally Posted by Caleb View Post
    True, but just because you use sessions does not ensure security, there are ways to use them.. and ways to not.
    True... the only reason I really find I use Cookies is like someone said above, if a user needs/wants to stay logged in. Or in other situations if you're logging information about the user (like visitor tracking type thing).

    Now I do have to disagree with the other thing Caleb said about most people not knowing how to make Cookies secure.... well it's not really any different than Sessions.... as long as you one-way-encrypt the password before storing it you're pretty much good to go (oh, and you just have to make sure the cookie doesn't never expire).... ya...

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •