|
Posted by S. Pidgorny on April 28, 2008, 5:51 pm
If you were Registered and logged in, you could reply and use other advanced thread options No - for the same reasons. Why do you need extravagant authentication-like
schemes when many proper ways of authentication are available?
If you just need to allow certain IPs to access the Web site, just configure
restrictions and use anonymous access.
--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-
* http://sl.mvps.org * http://msmvps.com/blogs/sp *
> Most of my users are behind their company's firewall. If I keep a database
> of firewall ip-numbers and check incoming requests against the database,
> wouldn't that be an ok solution?
> Steve Riley [MSFT] wrote:
>> Wrong approach. IP addresses identify machines, not humans. They are
>> easily spoofable, since they are always clear-text and are always
>> unauthenticated. Plus, with your approach, authorized users will be tied
>> to specific machines--they won't be able to access their information from
>> other computers.
>>
>> User ID/password pairs are specifically designed for the scenario you've
>> described. Please use them.
>>
|