In a quick note from the offices of PHP Magazine there's talk about session security and what measures can be taken to keep them safe.
Chris Shiflett, who wrote the cover story the December 2003 issue of PHP Magazine, has been kind enough to accept submissions from people who think they have a good implementation for securing sessions. In exchange, he will (hopefully) be able to reply to each person with a review of their implementation. He then plans to compile a list of his favorite techniques, and it could turn into another full-fledged article, that will be given away FREE through PHP Magazine. To turn in your submission, email Chris at shiflett@php.net.
A resource like this would be quite handy to have around, especially for those out there concerned that PHP isn't secure enough for their sites. The compiled techniques Chris publishes might even make a nice addition to the manual someday...




