There are some other very serious security issues with cookie store as
it stands now.

As I said earlier, I'm waiting for a spec and sample app before
working on a full review.  If those never happen, I'll eventually post
the sketches that I already have.  But I think the community would be
happier with a material "this is how the app can be compromised" over
"theoretically, depending on the implementation, this might be the
problem."  Anyway, if I don't here back on those things, I'll post my
notes from conversation - if I do, I'll try to get a full review done.

On Mar 27, 12:05 pm, "Alexey Verkhovsky" <[EMAIL PROTECTED]>
wrote:
> +1 to:
>
> CookieStore should be either (1) secure against replay
>
> > attacks by default, or (2) not the default session store. Anything
> > else is asking too much of non-security-aware developers.


--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups "Ruby 
on Rails: Core" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at 
http://groups.google.com/group/rubyonrails-core?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to