3 ms·
RFC 6896 – Secure Cookie Sessions for HTTP
- jamieson-becker 8y ago@moderators should probably be marked [2013]
- kpcyrd 8y agoIt seems this has all disadvantages of jwt-style sessions, plus a BREACH-style vulnerability in the crypto due to compression if `plain-text-cookie-value` contains data an attacker can taint.
- chrismorgan 8y agoA better title: RFC 6896 - SCS: KoanLogic's Secure Cookie Sessions for HTTP [2013]
- jedisct1 8y agoA better better title: RFC 6896 - SCS: KoanLogic's Insecure Cookie Sessions for HTTP [2013]
- kerng 8y agoThis doesn't seem to protect from Pass the Cookie attacks. Edit - it's a common red teaming tactic: https://wunderwuzzi23.github.io/blog/passthecookie.html https://wunderwuzzi23.github.io/blog/passthecookie.html