AFAIR the session ID is stored in a cookie for all the other session
stores. Doesn't much of what you say apply to the entire Rails session
system?

On Mar 30, 2:23 am, "S. Robert James" <[EMAIL PROTECTED]> wrote:
> Aside from the replay attacks discussed, there are some other attack
> vectors on the cookie_session store.


--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups "Ruby 
on Rails: Core" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at 
http://groups.google.com/group/rubyonrails-core?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to