1 |
Hi! |
2 |
|
3 |
On Mon, 07 Mar 2011, Mike Frysinger wrote: |
4 |
> >> If *anybody* can't use SSL for any reason please yell so that we can |
5 |
> >> decide if we leave it as it is (plain + encrypted) or not. |
6 |
> > |
7 |
> > Is there any *real* reason to force SSL? It is *hell* slow. |
8 |
> |
9 |
> it should of course be force for logging in |
10 |
|
11 |
If it is enforced for login, it should be enforced for logged |
12 |
in sessions, cf. Cookie stealing (for a POC: Firesheep). And no, |
13 |
restricting the login cookie to an IP is *not* "safe enough". |
14 |
|
15 |
Regards, |
16 |
Tobias |
17 |
|
18 |
-- |
19 |
Sent from aboard the Culture ship |
20 |
GSV Zero Gravitas |