Go Back   Webforumz.com > Blogs > The Web for Idiots by Idiots.

Notices


The Web 2.1 for Idiots!

!! We can be Digg-ed by clicking here. !!

ATTENTION: Work on the newest open directory/ search engine/ social network hybrid has begun.Any Questions?


This is the only blog where low-calcium is ok!


Welcome to the humble blog for Idiots, its almost like Web 2.1 for Dummies. EXCEPT its more blunt and half as much sodium.

I own various web-sites here and there and I'll be bloging about the extraneous task of making them from not-so-great to fantastic (in 3 easy years.) Enjoy!

Portal backed by 128-bit Secure connection - the Seal Portal Proje

Posted Feb 6th, 2008 at 19:16 by TheSealPortalTeam
Updated Feb 6th, 2008 at 19:19 by TheSealPortalTeam (Revised a question into a statement - CA)
Finally the Seal Portal now accepts secure connections for preventing your personal information from leaking to a third party person.

The SSL Certificate was registered with the GoDaddy.com Register and snapped into the framework with a breeze. (After a few frustrating moments with my personal certificate. Oh well, I shouldn't be self-certifying anyway!)

Now that the certificate is in place, here is some information on our unique registration process.

What registering really does, behind the scenes.
It connects to a user authorization database. It creates 2 entries. One is the users personal information the second is the users name and password.
This splits the two database making it harder for hackers and third parties to identify your personal information with your email address and password.
ALTHROUGH there is a unique ID number generated that tells the portal that the two are linked.
How your password is used in the system:
It isn't, its only used at the end of a connection to make sure your user name and password match. It is never called upon though out the entire framework of the seal portal.
Your e-mail address defines you but your user ID defines whats yours:
The Seal Portal team decided to distant your e-mail address for as much as possible from user-to-server transactions. Instead one session value is used containing your user ID which the Seal Portal uses for all user specific database transactions. Protecting your email address from potential security risk.
Of course I might of missed a few security protocols and might need reminding of them. So if you have any suggestions feel free to post/comment them here. Enjoy!


Total Comments 2

Comments

Old
alexgeek's Avatar
Were you required to change any of your backend code to work with the certificate?
permalink
Posted Feb 6th, 2008 at 20:33 by alexgeek alexgeek is offline
Old
TheSealPortalTeam's Avatar
I had to add code to the Log-In and Registering page to check if you have a secure connection, if not it gives you one.

Other than that the code itself was not changed for the most part.
permalink
Posted Feb 7th, 2008 at 11:54 by TheSealPortalTeam TheSealPortalTeam is offline
 
Total Trackbacks 0

Trackbacks

Recent Blog Entries by TheSealPortalTeam

All times are GMT. The time now is 22:17.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC8
© 2003-2008 Webforumz.com : All Rights Reserved

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43