4 ms·
Why encrypt the cookie at all? Why not just have server1 sign it and haver server2 verify server1's signature?
by achille 17y ago
Why encrypt the cookie at all? Why not just have server1 sign it and haver server2 verify server1's signature?
- NateLawson 17y agoThe point of the article is that some people use encryption to try to achieve authentication, which doesn't work. You're right. Signatures are appropriate for providing authentication. HMAC is a form of symmetric authentication.