Hashing a session fingerprint really necessary?

Viewed 5582

Please read this THOUROUGHLY before voting...

So I have seen a lot of session management classes that create a fingerprint via concatenation of user agent and a couple of ip blocks or whatever. They seem to also add a salt and then hash this fingerprint before storing it in a session variable.

This fingerprint generation typically happens every request in order to verify that the current user of the session is in deed the original session user. This is why I am wondering, is the salt and hash really necessary on something like this?

If a hacker can get onto your filesystem to see your session file contents, aren't you already hosed at that point?

Any info greatly appreciated.

8 Answers
Related