2 ms·
You really need to be careful how you implement the signing of these types of systems. I have broken several of these systems and extracted the secret key. If y
by timtadh 13y ago
You really need to be careful how you implement the signing of these types of systems. I have broken several of these systems and extracted the secret key. If you can extract the secret key, you can essentially become anyone and do anything that is controlled by the state in the cookie. Properly implemented, this shouldn't be a problem. I recommend having a separate key for each client session and storing the sessions in something fast and ephemeral like memcache. This has the advantage of also giving you a place to store another secret key for CSRF mitigation. Storing information in the cookie is convenient but it isn't without its risks.
- Patrick_Devine 13y agoThat kind of defeats the purpose of what's being proposed. Why wouldn't you just store all of the data in memcache instead of just the key? If you lost the memcache you're losing all of your sessions either way. One way you could get around it would be some kind of time based key like an RSA token. That way each of the servers would know all of the tokens a priori and you only accept that token for a limited period of time. Not perfect, but you still benefit from not being tied to your database.