On Mon, Mar 7, 2011 at 9:48 AM, Tobias Klausmann wrote: > On Mon, 07 Mar 2011, Mike Frysinger wrote: >> >> If *anybody* can't use SSL for any reason please yell so that we can >> >> decide if we leave it as it is (plain + encrypted) or not. >> > >> > Is there any *real* reason to force SSL? It is *hell* slow. >> >> it should of course be force for logging in > > If it is enforced for login, it should be enforced for logged > in sessions, cf. Cookie stealing (for a POC: Firesheep). And no, > restricting the login cookie to an IP is *not* "safe enough".
you're talking about two different things. imo it's more important to protect the credentials than spoofing/replay attacks. the former is a no brainer while the latter is fine to leave to the discretion of the end user. -mike
