On Mar 22, 3:21 pm, "Jeremy Evans" <[EMAIL PROTECTED]> wrote: > It's possible mitigate the problem somewhat by having an expiration > time put into the session (which cannot be modified by an attacker due > to the HMAC). However, you still won't be able to manually expire > sessions (i.e. log out). This will only help in cases where the attacker wants to steal someone's identity. But there are other uses of a replay attack - like the example I initially mentioned - where this won't help at all. And even in the identity theft case - what's to stop the attacker from using the computer 5 minutes after I leave? In general, I'd offer the amount of confusion on this thread as the best evidence that the average developer shouldn't have to deal with these issues by default. --~--~---------~--~----~------------~-------~--~----~ You received this message because you are subscribed to the Google Groups "Ruby on Rails: Core" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [EMAIL PROTECTED] For more options, visit this group at http://groups.google.com/group/rubyonrails-core?hl=en -~----------~----~----~----~------~----~------~--~---
- [Rails-core] Re: Replay attacks with cookie ... Brad Ediger
- [Rails-core] Re: Replay attacks with cookie ... Pete Yandell
- [Rails-core] Re: Replay attacks with cookie ... S. Robert James
- [Rails-core] Re: Replay attacks with cookie ... Daniel N
- [Rails-core] Re: Replay attacks with cookie ... Brad Ediger
- [Rails-core] Re: Replay attacks with cookie session Courtenay
- [Rails-core] Re: Replay attacks with cookie sess... Patrick Ritchie
- [Rails-core] Re: Replay attacks with cookie sess... Brad Ediger
- [Rails-core] Re: Replay attacks with cookie ... Jeremy Evans
- [Rails-core] Re: Replay attacks with cookie ... Brad Ediger
- [Rails-core] Re: Replay attacks with cookie ... S. Robert James
- [Rails-core] Re: Replay attacks with cookie session Neil Wilson
- [Rails-core] Re: Replay attacks with cookie sess... Brad Ediger
- [Rails-core] Re: Replay attacks with cookie ... Neil Wilson
- [Rails-core] Re: Replay attacks with cookie ... Brad Ediger
- [Rails-core] Re: Replay attacks with cookie ... Alexey Verkhovsky
- [Rails-core] Re: Replay attacks with cookie ... S. Robert James
- [Rails-core] Re: Replay attacks with cookie ... Brad Ediger
- [Rails-core] Re: Replay attacks with cookie ... Thijs van der Vossen
- [Rails-core] Re: Replay attacks with cookie ... Sam Bravard
- [Rails-core] Re: Replay attacks with cookie ... Thijs van der Vossen
