Alex Rivera | Logout

Is it advisable to store a hashed password in a cookie?

Asked 2010-03-02T04:13:24.007
18

I want user's to be able to select a "remember me" box on my website so they need not log in each time they come. So, I need to store a unique ID in a cookie to identify them. Is it safe to hash their password with sha512 and a long salt in PHP and store that value in the cookie? If the cookie was stolen, would their password be at risk? Obviously it must be connected to their password somehow, otherwise if the cookie value was guessed or stolen, the user would not be able to stop someone else logging in.

Also, is it advisable to use a GUID at all as the unique identifier?

Thanks, Ben

Edit
Report

1 Answer

5

There's a low risk with a good algorithm and large salt, but why take any unnecessary risk?

If you just need to identify the user, then store something that can uniquely identify the user, like a guid along with some other stored verification code (not their password, some random long string). I wouldn't use a guid alone as it would not be a safe method of authentication.

answered 2010-03-02T04:20:11.230

Your Answer