4 ms·
3) session_id is different from session_secret (generated also for you with SecureRandom, but also there you can change it)
by DAddYE 14y ago
3) session_id is different from session_secret (generated also for you with SecureRandom, but also there you can change it)
- tekacs 14y agoI would be very glad to hear that a session_secret is being used to encrypt session cookies (which would prevent the (working-at-the-time) 'attack' I posted in the abovementioned issue). I can't tell at a glance whether this change was made after the issue and if the problem is now overcome, but I'm glad to hear that security is at least on your minds! Just switching to BCrypt from the old DES'd passwords is a wonderful step! Best of luck and thanks for the great project!
- DAddYE 14y agoThanks! BTW, I'm far to be that is 'secure' nothing is 'secure', but we are putting a lot of efforts in that way, crf tokens, rack-protection and so on ... so jump in the community and help us to improve security aspects. Thanks for all!
- Argorak 14y agoWe're using standard Rack and Sinatra when it comes to sessions. So clearly: yes, always has.