3 ms·
Cookies (over SSL) can work if you only have one site, to store a session id or such. Since cookies could be replayed, they can't be used with multiple sites (t
by samuellb 11y ago
Cookies (over SSL) can work if you only have one site, to store a session id or such. Since cookies could be replayed, they can't be used with multiple sites (that would be analogous to using the same password on multiple sites). Also, cookies are generally stored unencrypted on your hard drive.
Client certificates can be used with multiple sites, do not need to be changed if one of the sites that you use gets cracked, can be revoked from if stolen, etc. Also they are typically stored encrypted, either on a smart card or encrypted in your browser, unlike cookies.
Some of these problems with cookies can be solved with a central authentication server (a trusted third party). In that case the central authentication server would generate an unique session cookie for each site, when the user logs in, and send the cookies to each of the sites. All communication still has to be encrypted in a way that prevents replay attacks.