Gentoo Archives: gentoo-dev

From: Mike Frysinger <vapier@g.o>
To: gentoo-dev@l.g.o
Cc: Tobias Klausmann <klausman@g.o>
Subject: Re: [gentoo-dev] Bugzilla 4 migration
Date: Mon, 07 Mar 2011 15:02:36
Message-Id: AANLkTik3+WYL0fjqVFqKFtqex+FvFmmbgqyFfZLX4g44@mail.gmail.com
In Reply to: Re: [gentoo-dev] Bugzilla 4 migration by Tobias Klausmann
1 On Mon, Mar 7, 2011 at 9:48 AM, Tobias Klausmann wrote:
2 > On Mon, 07 Mar 2011, Mike Frysinger wrote:
3 >> >> If *anybody* can't use SSL for any reason please yell so that we can
4 >> >> decide if we leave it as it is (plain + encrypted) or not.
5 >> >
6 >> > Is there any *real* reason to force SSL? It is *hell* slow.
7 >>
8 >> it should of course be force for logging in
9 >
10 > If it is enforced for login, it should be enforced for logged
11 > in sessions, cf. Cookie stealing (for a POC: Firesheep). And no,
12 > restricting the login cookie to an IP is *not* "safe enough".
13
14 you're talking about two different things. imo it's more important to
15 protect the credentials than spoofing/replay attacks. the former is a
16 no brainer while the latter is fine to leave to the discretion of the
17 end user.
18 -mike