ExternalAuth
Cantor, Scott
cantor.2 at osu.edu
Thu Dec 26 10:43:08 EST 2013
On 12/26/13, 10:15 AM, "Nick Amon" <namon at xceedium.com> wrote:
>The cookie will be addressed bound but even if it wasn't why would it be
>worthless? The same logic will apply, if the value of the cookie, a
>unique, random session ID, is found in the database, it is valid. Even
>if the same cookie was presented to a different instace of our software,
>it wouldn't be accepted because presumably the session ID will not be in
>the database. Am I misunderstanding something?
Cookie theft is just not that hard to pull off and browsers are a security
cesspool. Adding a requirement to spoof an address raises the bar a fair
amount.
-- Scott
More information about the users
mailing list