Gentoo Archives: gentoo-dev

From: Tobias Klausmann <klausman@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Bugzilla 4 migration
Date: Mon, 07 Mar 2011 14:49:03
Message-Id: 20110307144819.GA28374@kaini.schwarzvogel.de
In Reply to: Re: [gentoo-dev] Bugzilla 4 migration by Mike Frysinger
1 Hi!
2
3 On Mon, 07 Mar 2011, Mike Frysinger wrote:
4 > >> If *anybody* can't use SSL for any reason please yell so that we can
5 > >> decide if we leave it as it is (plain + encrypted) or not.
6 > >
7 > > Is there any *real* reason to force SSL? It is *hell* slow.
8 >
9 > it should of course be force for logging in
10
11 If it is enforced for login, it should be enforced for logged
12 in sessions, cf. Cookie stealing (for a POC: Firesheep). And no,
13 restricting the login cookie to an IP is *not* "safe enough".
14
15 Regards,
16 Tobias
17
18 --
19 Sent from aboard the Culture ship
20 GSV Zero Gravitas

Replies

Subject Author
Re: [gentoo-dev] Bugzilla 4 migration Dane Smith <c1pher@g.o>
Re: [gentoo-dev] Bugzilla 4 migration Mike Frysinger <vapier@g.o>
Re: [gentoo-dev] Bugzilla 4 migration "Michał Górny" <mgorny@g.o>