|
|||||||||||
|
Re: How to protect against cookie stealing?
From: Marc Slemko <marcs(at)znep.com>
Date: Sun Jul 27 2003 - 12:32:22 EDT The authentication token is not the holy grail: I don't need a user's cookie or SSL certificate or cereal box decoder ring if I can just tell their browser to jump through a given series of actions on a site and then send the results off via a HTTP request to some other site. Don't get me wrong, ensuring your authentication scheme is secure against a variety of attacks is good. But don't forget the bigger picture. Received on Sun Jul 27 17:11:36 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:54 EDT |
||||||||||
|
|||||||||||