Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The point the GP was trying to make, I think, is that if the site's operator has cared enough about their own security to cryptographically sign their cookies, then this provides security to the users as a free benefit, because a MITM wanting to attack the user doesn't have the site's signing key either.


Cookie signing doesn't fix this. Attacker will just login, take his own signed, valid, session cookies, shove them into Victim. Now Victim uses whatever.com and Attacker can see.

The example they gave was being able to do this to Gmail. Victim is logged into Gmail, but the Gmail Chat widget is logged in as Attacker.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: