
Originally Posted by
djr33
Trial and error. The problem is that hackers have infinite time to try to hack your site, while you only have limited time to develop it.
What you've described sounds good. The only way to continue checking it is to try to hack it yourself or imagine how someone else might. How could someone steal a session or steal a password? If you can't think of it, you're at least fairly safe.
One thing that helps: you are designing this yourself and the system is unique. That fact means that you won't have people attacking your site or knowing anything about it. This is different than a shared system like a common bulletin board, wordpress, etc. This means that the target is smaller, not that it's 100% secure, but it does help.
Bookmarks