7 ms·
> as the encrypted cookie can be sniffed, and replayed to the server I think the whole article is premised on requiring a level of security that would presume
by zmimon 17y ago
> as the encrypted cookie can be sniffed, and replayed to the server
I think the whole article is premised on requiring a level of security that would presume TLS is being used.
- NateLawson 17y agoYes, the focus is on preventing cookie forgery for pre-auth account compromise or privilege escalation.