Secure credential storage between website visits

I am creating a website that allows users to create accounts and access the contents of the site. I don’t want users to register every time they visit the site, so I plan to store the username and password in a cookie. However, I heard that this is bad practice, even if the password hashed a cookie.

What "best practices" should be followed to safely remember user credentials between visits to my website?

+3
source share
4 answers

Never do that. Throw passwords in the open.

The safest method:

, - , - - , . , . , , (, 15 ). cookie.

, , , , , , . , cookie. , cookie.

Edit:

. .

. , , . , , , , md5 sha.

, - , , . attacs .. , cookie . 100% .

, https. cookie .

:

IP- . IP- NAT ..

+2

, , .

:

  • cookie , ,
  • cookie, .

, , .

, , , .

+2

cookie. .

. ?

+1

cookie " ".

However, for sensitive areas of the system, you need to know that the user has entered the system into cached credentials so that you can offer a username / password prompt before allowing them to do any real damage. This can be held as a session-based flag.

0
source

Source: https://habr.com/ru/post/1704120/


All Articles