Question about Shib session cookie protection
Wessel, Keith
kwessel at illinois.edu
Tue Nov 5 17:09:04 EST 2013
All,
I had a question posed to me this afternoon about how Shib SP session cookies are protected during transport when the SP isn't using https. If a hacker listens in on http traffic and grabs a user's session cookie and can then use the same IP as that user (such as a coffee shop with a nat'd setup), what's keeping the hacker from using the user's session?
Of course, using an https transport is the best way to go, but this is for the odd case where http is being used.
I see nothing on the wiki about this. Can anyone shed any light on what keeps this cookie from being stolen?
Keith
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131105/5d1b89f2/attachment.html
More information about the users
mailing list