4 ms·
thank you. But this totally lacks security. What if someone steals the cookie?
by yassersouri 16y ago
thank you. But this totally lacks security. What if someone steals the cookie?
- bl4k 16y agoyou are screwed either way. that is what Firesheep does the solution is to use SSL and set the secure flag on the cookie
- yassersouri 16y agoI mean what if some one steals your cookie from your machine and copies it to his machine, this way he can login as you. I feel there is a way to prevent this, but I have no idea
- bl4k 16y agono way to prevent it, just the way it works. there you are relying on local machine security and the user not keeping themselves logged in, etc. do use SSL, though