3 ms·
That only protects the user's password. The auth cookie will be sent in all subsequent requests in plain text. EDIT: that's how firesheep (https://en.wikipedia
by oxplot 5y ago
That only protects the user's password. The auth cookie will be sent in all subsequent requests in plain text.
EDIT: that's how firesheep (https://en.wikipedia.org/wiki/Firesheep https://en.wikipedia.org/wiki/Firesheep) hijacked sessions for e.g.
- nly 5y agoThat's not true. Cookies can have a 'secure' attribute which tells the browser to send them only over TLS
- eli 5y agoin 2011?
- shkkmo 5y agoYes
- chc 5y agoBut that just makes your login not work if the rest of your site is HTTP, doesn't it?
- shkkmo 5y agoYou should not show authenticated pages without HTTPS
- oxplot 5y agoA secure cookie would be of no use for a site whose only secure page is the login page, which is what the parent post I replied to was talking about.