On 23/03/2007, at 6:19 AM, Brad Ediger wrote:
> (a) Cookie sessions are vulnerable to replay attacks, because the > client can present *any* cookie that it has seen to the server, not > just the most recently sent one. On the other hand, server-side > storage methods are not vulnerable because the session ID always > references the latest version of the session. +1 for hitting the nail on the head. --~--~---------~--~----~------------~-------~--~----~ You received this message because you are subscribed to the Google Groups "Ruby on Rails: Core" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [EMAIL PROTECTED] For more options, visit this group at http://groups.google.com/group/rubyonrails-core?hl=en -~----------~----~----~----~------~----~------~--~---
