<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to avoid Identity Theft in Zend Framework with Zend Auth</title>
	<atom:link href="http://phpdev.ro/how-to-avoid-identity-theft-in-zend-framework-with-zend-auth.html/feed" rel="self" type="application/rss+xml" />
	<link>http://phpdev.ro/how-to-avoid-identity-theft-in-zend-framework-with-zend-auth.html</link>
	<description>The blog of Andrei Gabreanu</description>
	<lastBuildDate>Thu, 03 May 2012 07:45:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.1</generator>
	<item>
		<title>By: Elwin</title>
		<link>http://phpdev.ro/how-to-avoid-identity-theft-in-zend-framework-with-zend-auth.html#comment-873</link>
		<dc:creator>Elwin</dc:creator>
		<pubDate>Mon, 28 Feb 2011 22:05:56 +0000</pubDate>
		<guid isPermaLink="false">http://phpdev.ro/?p=987#comment-873</guid>
		<description>Is there no option to see where the user came from the last visited page? If so can you not use that value to validate if it is still the same user or someone that stole the cookie?</description>
		<content:encoded><![CDATA[<p>Is there no option to see where the user came from the last visited page? If so can you not use that value to validate if it is still the same user or someone that stole the cookie?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elwin</title>
		<link>http://phpdev.ro/how-to-avoid-identity-theft-in-zend-framework-with-zend-auth.html#comment-328</link>
		<dc:creator>Elwin</dc:creator>
		<pubDate>Mon, 28 Feb 2011 17:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://phpdev.ro/?p=987#comment-328</guid>
		<description>Is there no option to see where the user came from the last visited page? If so can you not use that value to validate if it is still the same user or someone that stole the cookie?</description>
		<content:encoded><![CDATA[<p>Is there no option to see where the user came from the last visited page? If so can you not use that value to validate if it is still the same user or someone that stole the cookie?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Comment éviter le vol d'identité dans vos applications Zend Framework avec le composant Zend_Auth &#124; Itanea le Blog</title>
		<link>http://phpdev.ro/how-to-avoid-identity-theft-in-zend-framework-with-zend-auth.html#comment-872</link>
		<dc:creator>Comment éviter le vol d'identité dans vos applications Zend Framework avec le composant Zend_Auth &#124; Itanea le Blog</dc:creator>
		<pubDate>Thu, 20 Jan 2011 12:18:05 +0000</pubDate>
		<guid isPermaLink="false">http://phpdev.ro/?p=987#comment-872</guid>
		<description>[...] du traducteur : Cet article est une traduction de l&#8217;article How to avoid Identity Theft in Zend Framework with Zend Auth paru le 04 mars 2010 sur PHP Tutorials, écrit par Andrei Gabreanu. Je le remercie au passage de [...] </description>
		<content:encoded><![CDATA[<p>[...] du traducteur : Cet article est une traduction de l&#8217;article How to avoid Identity Theft in Zend Framework with Zend Auth paru le 04 mars 2010 sur PHP Tutorials, écrit par Andrei Gabreanu. Je le remercie au passage de [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrei Gabreanu</title>
		<link>http://phpdev.ro/how-to-avoid-identity-theft-in-zend-framework-with-zend-auth.html#comment-870</link>
		<dc:creator>Andrei Gabreanu</dc:creator>
		<pubDate>Sun, 13 Jun 2010 00:41:58 +0000</pubDate>
		<guid isPermaLink="false">http://phpdev.ro/?p=987#comment-870</guid>
		<description>Nice ideea with the Zend Session validator! I actually overlooked it! Thanks for the ideea.&lt;br&gt;&lt;br&gt;Regarding the user agents, yes of course, you are right. This plugin was never intended to be of a large scale use (ex a public website ) rather than a portion of an app where you *know* who will access it and with what user agents etc . Prolly should have said that somewhere in the post :)</description>
		<content:encoded><![CDATA[<p>Nice ideea with the Zend Session validator! I actually overlooked it! Thanks for the ideea.</p>
<p>Regarding the user agents, yes of course, you are right. This plugin was never intended to be of a large scale use (ex a public website ) rather than a portion of an app where you *know* who will access it and with what user agents etc . Prolly should have said that somewhere in the post <img src='http://phpdev.ro/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrei Gabreanu</title>
		<link>http://phpdev.ro/how-to-avoid-identity-theft-in-zend-framework-with-zend-auth.html#comment-871</link>
		<dc:creator>Andrei Gabreanu</dc:creator>
		<pubDate>Sun, 13 Jun 2010 00:40:07 +0000</pubDate>
		<guid isPermaLink="false">http://phpdev.ro/?p=987#comment-871</guid>
		<description>Agree. It is more of a convenience way to check something like, lets say for example an admin page where you *know* who will access thus you don&#039;t mind the user agents changing.</description>
		<content:encoded><![CDATA[<p>Agree. It is more of a convenience way to check something like, lets say for example an admin page where you *know* who will access thus you don&#39;t mind the user agents changing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pieter</title>
		<link>http://phpdev.ro/how-to-avoid-identity-theft-in-zend-framework-with-zend-auth.html#comment-869</link>
		<dc:creator>Pieter</dc:creator>
		<pubDate>Sun, 13 Jun 2010 00:38:15 +0000</pubDate>
		<guid isPermaLink="false">http://phpdev.ro/?p=987#comment-869</guid>
		<description>Nice post. Just a small hint; you can actually do everything you&#039;re trying to do with Zend_Session already. Just add the necessary validators (in your case user_agent and ip validator) to Zend_Session using Zend_Session::registerValidator().&lt;br&gt;I must warn you though; validating on user_agent is probably not a smart thing to do as more and more browsers tend to change their user agent string during a session (e.g. IE8).</description>
		<content:encoded><![CDATA[<p>Nice post. Just a small hint; you can actually do everything you&#39;re trying to do with Zend_Session already. Just add the necessary validators (in your case user_agent and ip validator) to Zend_Session using Zend_Session::registerValidator().<br />I must warn you though; validating on user_agent is probably not a smart thing to do as more and more browsers tend to change their user agent string during a session (e.g. IE8).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrei Gabreanu</title>
		<link>http://phpdev.ro/how-to-avoid-identity-theft-in-zend-framework-with-zend-auth.html#comment-72</link>
		<dc:creator>Andrei Gabreanu</dc:creator>
		<pubDate>Sat, 12 Jun 2010 19:41:00 +0000</pubDate>
		<guid isPermaLink="false">http://phpdev.ro/?p=987#comment-72</guid>
		<description>Nice ideea with the Zend Session validator! I actually overlooked it! Thanks for the ideea.

Regarding the user agents, yes of course, you are right. This plugin was never intended to be of a large scale use (ex a public website ) rather than a portion of an app where you *know* who will access it and with what user agents etc . Prolly should have said that somewhere in the post :)</description>
		<content:encoded><![CDATA[<p>Nice ideea with the Zend Session validator! I actually overlooked it! Thanks for the ideea.</p>
<p>Regarding the user agents, yes of course, you are right. This plugin was never intended to be of a large scale use (ex a public website ) rather than a portion of an app where you *know* who will access it and with what user agents etc . Prolly should have said that somewhere in the post <img src='http://phpdev.ro/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrei Gabreanu</title>
		<link>http://phpdev.ro/how-to-avoid-identity-theft-in-zend-framework-with-zend-auth.html#comment-71</link>
		<dc:creator>Andrei Gabreanu</dc:creator>
		<pubDate>Sat, 12 Jun 2010 19:40:00 +0000</pubDate>
		<guid isPermaLink="false">http://phpdev.ro/?p=987#comment-71</guid>
		<description>Agree. It is more of a convenience way to check something like, lets say for example an admin page where you *know* who will access thus you don&#039;t mind the user agents changing.</description>
		<content:encoded><![CDATA[<p>Agree. It is more of a convenience way to check something like, lets say for example an admin page where you *know* who will access thus you don&#8217;t mind the user agents changing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pieter</title>
		<link>http://phpdev.ro/how-to-avoid-identity-theft-in-zend-framework-with-zend-auth.html#comment-70</link>
		<dc:creator>Pieter</dc:creator>
		<pubDate>Sat, 12 Jun 2010 19:38:00 +0000</pubDate>
		<guid isPermaLink="false">http://phpdev.ro/?p=987#comment-70</guid>
		<description>Nice post. Just a small hint; you can actually do everything you&#039;re trying to do with Zend_Session already. Just add the necessary validators (in your case user_agent and ip validator) to Zend_Session using Zend_Session::registerValidator().
I must warn you though; validating on user_agent is probably not a smart thing to do as more and more browsers tend to change their user agent string during a session (e.g. IE8). </description>
		<content:encoded><![CDATA[<p>Nice post. Just a small hint; you can actually do everything you&#8217;re trying to do with Zend_Session already. Just add the necessary validators (in your case user_agent and ip validator) to Zend_Session using Zend_Session::registerValidator().<br />
I must warn you though; validating on user_agent is probably not a smart thing to do as more and more browsers tend to change their user agent string during a session (e.g. IE8).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michiel Brandenburg</title>
		<link>http://phpdev.ro/how-to-avoid-identity-theft-in-zend-framework-with-zend-auth.html#comment-868</link>
		<dc:creator>Michiel Brandenburg</dc:creator>
		<pubDate>Thu, 10 Jun 2010 03:33:23 +0000</pubDate>
		<guid isPermaLink="false">http://phpdev.ro/?p=987#comment-868</guid>
		<description>Nice post, mind u turning on the useragent check will be more trouble than it&#039;s worth.  Ajax calls from the same browser being used can report different useragents, on top of that the useragent can be configured by the user.  Also take note that you might have to check for the presence of X-Forwarded-For headers (these can be faked) but it might indicate that the user is behind a proxy and the ip might not be trusted.</description>
		<content:encoded><![CDATA[<p>Nice post, mind u turning on the useragent check will be more trouble than it&#39;s worth.  Ajax calls from the same browser being used can report different useragents, on top of that the useragent can be configured by the user.  Also take note that you might have to check for the presence of X-Forwarded-For headers (these can be faked) but it might indicate that the user is behind a proxy and the ip might not be trusted.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced)
Database Caching 2/3 queries in 0.001 seconds using disk
Object Caching 305/305 objects using disk

Served from: phpdev.ro @ 2012-05-19 01:16:15 -->
