<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Post-dissertation development</title>
	<link>http://www.screwlessdesign.co.uk/blog/post-dissertation-development/</link>
	<description>project and assignment diary</description>
	<pubDate>Tue, 06 Jan 2009 00:10:46 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>

	<item>
		<title>by: Stephen Lang</title>
		<link>http://www.screwlessdesign.co.uk/blog/post-dissertation-development/#comment-65</link>
		<pubDate>Wed, 13 Aug 2008 21:48:38 +0000</pubDate>
		<guid>http://www.screwlessdesign.co.uk/blog/post-dissertation-development/#comment-65</guid>
					<description>Looks like the secure user login system is going to have to wait a while as I only have a shared SSL certificate at the minute, meaning I can't use cookies between domains and so my idea for secure user authentication will not work.

I have read about secure AJAX login systems that utilise client-side authentication... but what about devices that do not support JavaScript? Either I have to accept that these users must transmit their login information securely or I buy a dedicated SSL certificate... Is it worth it though? I'll have to find out the price first. I would ideally prefer that the user's entire session is secure, especially given that user's may store their credentials for several different applications in their accounts...

More soon.</description>
		<content:encoded><![CDATA[<p>Looks like the secure user login system is going to have to wait a while as I only have a shared SSL certificate at the minute, meaning I can&#8217;t use cookies between domains and so my idea for secure user authentication will not work.</p>
<p>I have read about secure AJAX login systems that utilise client-side authentication&#8230; but what about devices that do not support JavaScript? Either I have to accept that these users must transmit their login information securely or I buy a dedicated SSL certificate&#8230; Is it worth it though? I&#8217;ll have to find out the price first. I would ideally prefer that the user&#8217;s entire session is secure, especially given that user&#8217;s may store their credentials for several different applications in their accounts&#8230;</p>
<p>More soon.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
