|
|||||||||||
|
Re: Session Fixation
From: Alex Russell <alex(at)netWindows.org>
Date: Tue Apr 01 2003 - 15:33:19 EST -----BEGIN PGP SIGNED MESSAGE-----
On Tuesday 01 April 2003 12:33 pm, Matt Fisher wrote:
wow. What a mess. Although I suppose the blame lies much more with the permissive nature of IE than with WMP per sae. > > Has anyone put the Internet Explorer ^Super Cookie^ to use ?
Given the above discription, you shold note that trusting said "super-cookie" is no better than an IP because it is something that _you didn't issue_. If you didn't issue it, you can't verify it. If you can't verify it, you can't trust it (PKI is the notable exemption to the issuing rule, as you can verify without issuing). If you can't trust it, you shouldn't use it as a basis for security measures. I'm sure it's plenty unique (in the common case), however good security design (and good accessability design) strongly suggest that you design your app so that it continues to function correctly in the _uncommon_ case. Not just when the browser is being complicit in the degradation of its users privacy. Also, why should you count on the machine having WMP installed in the first place? And why should you rely on JavaScript?
iD8DBQE+ifePoV0dQ6uSmkYRAu5OAKCL1yB9CLOvOeGj1tv0BW2Jdfc/zwCgwyyJ
r/BZbi/9ftWYC0Aom8cZWlI=
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:50 EDT |
||||||||||
|
|||||||||||