Discussion in 'ASP General' started by c676228, Sep 13, 2009.

  1. c676228

    c676228 Guest

    Hi all,

    I have a question.

    I use a cookie to track where our sales come from so we can credit our sales
    agents. We assign a specific link to each of our agents like this and the
    number 123456 represent a specific agent and then we pass the following link
    to our agents.
    I will write the value 123456 to a cookie called mycookie.
    What I am worry about is this cookie's security.
    If a programmer from one of our agents office knows how we credit our agent,
    is it possible that their programmer immitate our program and even write his
    agent code on their customers' computers when those customers visit any pages
    on their site(domain) and look for some products similar to ours.
    Say when a customer visit and just
    browsing, not purchasing, but they wrote the exactly same cookie and value,
    our domain name to this customer's computer like this. This cookie set never

    Response.Cookies("mycookie").Domain = ""

    Let's say two weeks later, this customer visit our site
    and try to purchase one of our products. This cookie value will be picked up
    since it was written on his/her computer two weeks ago. So the sales credit
    goes to this agent. Is it possible?
    c676228, Sep 13, 2009
  2. Hello Betty,

    You are right. Cookie is not secure. It stores in the client so that user
    can access it at anytime. Then cookie value will be as the QueryString in
    the url to say: pcn is always
    visible to the users.

    Is mycookie only worked for the registered user? I think this functionality
    is needed only if the registered user logged in. If so, my suggestion is
    this value can be as user profile stored into the sql server instead of
    cookie. It will be operated on server-side, and it isn't able to be touched
    directly on client side. So it will be more secure than using cookie.

    For the registered user, to keep the profile data for a long time, we can
    store the value into the sql server for security requirement.
    For the unregistered user, to keep the profile data for a long time, we can
    use cookie. But you had better implement an algorithm to encrypt cookies
    (In Asp.Net, we can buid HttpSecureCookie class to achieve it. In Classic
    Asp, as one of simple approach to encrypt cookie, you can check this


    Vince Xu [MSFT], Sep 14, 2009
  3. c676228

    Dooza Guest

    The domain name in the cookie protects other websites from picking up
    another websites cookies, so I don't think you have much to worry about.

    Dooza, Sep 15, 2009
  4. c676228

    c676228 Guest

    Vince and Steve,
    Thank you both for the input.
    I will think about server side implementation.
    c676228, Sep 28, 2009
