Solved

Should I use cookies or IPs or somethnig else to ID user ?

Posted on 2000-03-18
7
157 Views
Last Modified: 2013-12-25
Hi,

I've written my own shopping cart system which has been integrated into our existing retail system.

Is it wise for me to rely entirely on Cookies for session ID's ?

I know some people turn off cookies, I also know that IPs are even less reliable due to mass proxy usage by AOL style customers.

Any advice on this subject would be appreciated also any statistics on the number of people who can't / won't accept cookies would be useful in helping me make my decision.

I've heard of software which uses the IP when cookies are not accepted but woundl't this just cause more problems is a proxy was used ?

Thanks

Kevin
0
Comment
Question by:kgorrell
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 1

Expert Comment

by:chaduka
ID: 2631315
IMHO, cookies are better than IPs. There is a very high security risk when one uses IPs as compared to using cookies.

You will have to tell people who turn off cookies "tough luck"!!!

There are solutions to your problem though. Application servers like Cold Fusion allow you the developer to store session variables and other info in the you registry or database. This eliminates the problem of people who turn off cookies and (AOL) proxies.
0
 

Author Comment

by:kgorrell
ID: 2631338
It's not acceptable to tell them tough luck - maybe I'll just tell them to accept the cookie - this could be enough !

I'm assigning a cart ID to each user and using this as the cookie (or session ID) - the actual cart is stored in a database on the server.

From what I understand cold fusion, etc can't store anything more on the client PC otherwise I could recreate this method myself - I'm usng a cookie as a session ID variable. If this is correct about Cold Fusion can anyone explain how it's achieved at the raw HTTP level - I don't see it being possible though without using some sort of cookie like feature which is present in all the main browsers.

Kevin
0
 
LVL 1

Expert Comment

by:chaduka
ID: 2631349
Hmmm, "tough luck" was my wording. Of course you will have to tell them to accept the cookies.

Cold Fusion won't store anything on the client PC (except cookies of coz, something we want to avoid), but on the server machine itself. The client URL will contain a session ID which CF will use (among other variables you set) to identify the user/session/browser. You might want to ask in the Cold Fusion area on more about session management, or ask on http://forums.allaire.com.
0
Why You Need a DevOps Toolchain

IT needs to deliver services with more agility and velocity. IT must roll out application features and innovations faster to keep up with customer demands, which is where a DevOps toolchain steps in. View the infographic to see why you need a DevOps toolchain.

 

Author Comment

by:kgorrell
ID: 2631355
Thanks for the info - I understand what you mean about the cold fusion stuff and it won't work in this case.

My software allows affiliates to advertise and sell my goods on their websites by creating their own website and using 'Buy Me' style buttons which will create a new shopping cart the first time a user picks a product.

Once the user has confirmed they want to add the  item to the cart they are returned to the affiliates site which is under a different domain and server and not under my control.

I don't think that I would be able to pass back the information needed to a 3rd party site so it could be accessed when and if they click on the second item for the shopping cart.

Looks like it's probably cookies for me then !
0
 
LVL 3

Expert Comment

by:monas
ID: 2631663

0
 
LVL 84

Expert Comment

by:ozo
ID: 2632027
You could also use <input type=hiddeh> or
WWW-Authenticate: Basic
0
 
LVL 2

Accepted Solution

by:
a198298 earned 75 total points
ID: 2719385
I have created a Shopping Cart myself and used IP's at first.

I had a problem with this when connecting with X-Stream because the IP was misteriously changing. Since then I have used a cookies.

Read the cookie
If no cookie send out unique identifier.
If the cookie is there reuse the unique identifier.

This way the user can return even if they have a dynamic IP.
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Batch, VBS, and scripts in general are incredibly useful for repetitive tasks.  Some tasks can take a while to complete and it can be annoying to check back only to discover that your script finished 5 minutes ago.  Some scripts may complete nearly …
This article will show, step by step, how to integrate R code into a R Sweave document
The viewer will learn how to count occurrences of each item in an array.
The viewer will learn how to create and use a small PHP class to apply a watermark to an image. This video shows the viewer the setup for the PHP watermark as well as important coding language. Continue to Part 2 to learn the core code used in creat…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question