1 |
On Mon, Mar 7, 2011 at 9:48 AM, Tobias Klausmann wrote: |
2 |
> On Mon, 07 Mar 2011, Mike Frysinger wrote: |
3 |
>> >> If *anybody* can't use SSL for any reason please yell so that we can |
4 |
>> >> decide if we leave it as it is (plain + encrypted) or not. |
5 |
>> > |
6 |
>> > Is there any *real* reason to force SSL? It is *hell* slow. |
7 |
>> |
8 |
>> it should of course be force for logging in |
9 |
> |
10 |
> If it is enforced for login, it should be enforced for logged |
11 |
> in sessions, cf. Cookie stealing (for a POC: Firesheep). And no, |
12 |
> restricting the login cookie to an IP is *not* "safe enough". |
13 |
|
14 |
you're talking about two different things. imo it's more important to |
15 |
protect the credentials than spoofing/replay attacks. the former is a |
16 |
no brainer while the latter is fine to leave to the discretion of the |
17 |
end user. |
18 |
-mike |