3 ms·
To protect against only a passive eavesdropper if you aren't worried about replay or MITM you only need to do the authentication over SSL (What the writer lists
by Saavedro 17y ago
To protect against only a passive eavesdropper if you aren't worried about replay or MITM you only need to do the authentication over SSL (What the writer lists as #2 in the list of "normal ways" of handling the problem at the top of the post). And no, it does not prevent replay of short-term session cookies; It seems to only allow for the long-term "cookie" (which is never sent in cleartext. It isn't an actual browser "cookie") (the mentioned "Persistent Storage") to be used to generate more than one short-term cookie, even without SSL (though with as many SQL hits that it is proposed it would be doing it probably wouldn't perform any better, which is pretty much the point). So you're fine if your short-term session expires by the time your passive eavesdropper cares to try to use the intercepted data.