Hostmonster Sucks – Hostmonster Review and Warning
After 4 years of suffering and apologising to my clients about hostmonster’s downtime, I am moving my sites out of there, and I am leaving Hostmonster for good. In this article I will explain...
Startups & Software – Simple, Open and Pragmatic.
After 4 years of suffering and apologising to my clients about hostmonster’s downtime, I am moving my sites out of there, and I am leaving Hostmonster for good. In this article I will explain...
CakeOTP is a reference implementation of User Registration with a secure, table-less and expirable implementation of One Time Password for the popular CakePHP development framework.
I have been using CakePHP for a long time now and enjoy every second. It provides a productive, easy to use and well document platform for PHP application. The key advantages for me are – transparent OR mapping, a strong Model View Controller framework, and tons of extra utilities that make your life better.
I have came across a possible security issue in one of cakePHP code examples. This section of code is responsible to authorize or un-authorize clients access to a certain action (MVC flow)
action == 'delete') { if ($this->Auth->user('role') == 'admin') { return true; } else { return false; } } return true; } ?>
The major security rule this code is breaking is – never ever have ‘return true’ as a default for an authorization method.
CakeOTP is a secure, table-less and expirable implementation of One Time Password for the popular CakePHP development framework.
A one-time password (OTP) is a password that is only valid for a single login session or transaction. It is commonly used in the internet for registration and password reminder process in which OTPs are provides to the user in a form of a link that the user uses to access in order to create/reset his password.
The problem is that most one-time password implementation involve maintaining additional database tables and batch process that handle the persistence and expire date of the one time password. This adds complexity and reduces performance.
CakeOTP is a simple and clean implementation of one time password. It reduces complexity by removing the redundant SQL calls and DB batch maintenance while still keeping the one time password secure and expirable.
Download this release here.
Checkout the Online Demo, project page and getting started page.
I have started to implement the algorithm for tableless, secure One time password.
Here is a link to the Demo, and here is a link to the beta release.
The only thing you need to do other then the regular cakePHP setup is to create a user table (used by the CakePHP Auth component):
A one-time password (OTP) is a password that is only valid for a single login session or transaction. It is commonly used in the internet for registration and password reminder process in which OTPs are provides to the user in a form of a link that the user uses to access in order to create/reset his password.
Common requirements of One Time passwords are:
Most OTP implementations use a Database table to persist the OTP and to manage their expiry date, a DB table might look like this:
id | User Id | OTP | Expire date |
---|---|---|---|
1 | Amir | Asfsd3434bgddh | 1/1/2010 |
2 | Someone | Ddfsd3345ssfsss | 7/1/2010 |
While this is a valid solution, it is not the most efficient and elegant one, the truth is that you do not need an additional table enable and manage OTPs.
The answer is simple – the seed for this OTP is already persisted in the Database in the form of the old password (or more exactly the old password hash)
Here is how it is done: