Alex Rivera | Logout

How to anonymously identify a user and store that information

Asked 2010-12-14T23:39:56.043
11

I need a simple user identification system for the purpose of allowing/prohibiting an action.

This is not a high-security requirement and it is ok to make mistakes (eg same user will execute non-allowed action using different browsers).

To be less abstract, let's see at the StackOverflow voting and assume we want to allow voting by public audience, but only once.

The simplest thing that can work - is using a cookie: set a new cookie per answer; store all votes in one cookie (or combine these somehow).

This is a bit unreliable due to the limitations of a cookie size/number. It will also sent the cookie to the site all the time, while it is only required on 1 action.

So from this perspective I would like to avoid using cookie.
But don't see a better of doing this over a regular HTTP. I don't consider IP/MAC address etc.

So, with the context above, the questions is: how to anonymously identify a user and store that information on the client?

Thanks.

Edit
Report

1 Answer

1

MAC address would be awesome, but not possible over HTTP unfortunately (and a good thing for user privacy).

Cookie and IP address are your only options.

You can delete the cookie when you're done with it, only have it apply to the path that is relevant, or just have it expire in a few hours/days whatever is appropriate.

answered 2010-12-14T23:50:54.333

Your Answer