Question about Shib session cookie protection

Wessel, Keith kwessel at illinois.edu
Tue Nov 5 17:09:04 EST 2013


All,

I had a question posed to me this afternoon about how Shib SP session cookies are protected during transport when the SP isn't using https. If a hacker listens in on http traffic and grabs a user's session cookie and can then use the same IP as that user (such as a coffee shop with a nat'd setup), what's keeping the hacker from using the user's session?

Of course, using an https transport is the best way to go, but this is for the odd case where http is being used.

I see nothing on the wiki about this. Can anyone shed any light on what keeps this cookie from being stolen?

Keith

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131105/5d1b89f2/attachment.html 


More information about the users mailing list