Hi! 

On Mon, 07 Mar 2011, Mike Frysinger wrote:
> >> If *anybody* can't use SSL for any reason please yell so that we can
> >> decide if we leave it as it is (plain + encrypted) or not.
> >
> > Is there any *real* reason to force SSL? It is *hell* slow.
> 
> it should of course be force for logging in

If it is enforced for login, it should be enforced for logged
in sessions, cf. Cookie stealing (for a POC: Firesheep). And no,
restricting the login cookie to an IP is *not* "safe enough".

Regards,
Tobias

-- 
Sent from aboard the Culture ship
        GSV Zero Gravitas

Reply via email to