Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #3684

Re: session cookie: client side

From "sl@exabyte" <sb5309@hotmail.com>
Newsgroups comp.lang.php
Subject Re: session cookie: client side
Date 2011-11-04 22:21 +0800
Organization albasani.net
Message-ID <j90sdg$qle$1@news.albasani.net> (permalink)
References <j8tlr0$idi$1@news.albasani.net> <4147316.976.1320323017283.JavaMail.geo-discussion-forums@yqnv12> <j8vvsn$ub6$1@news.albasani.net> <j90jsq$550$1@dont-email.me>

Show all headers | View raw


> The cookie does not identify the user - it is just the session id. What 
> the server does with it is something else.
>
> In general, the session id does identify the computer from which the
> cookie is being sent because the session id is a rather long
> pseudo-random alphanumeric value.  Yes it's possible for someone else
> to intercept and read the session id, but in general it's unlikely.
>
> The real question is - what is the problem you are trying to resolve?
> If the data are that sensitive, you should be using a secure protocol
> for everything.  If the data aren't sensitive enough to require a
> secure protocol, why do you think the cookie is?

I think I am missing something. By the term 'secure protocol', ie SSL, 
implies that HTTPS be used, rather than HTTP, isn't it ?

Sorry if it is a stupid question. Anyway I shall google for SSL and HTTPS.

Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

session cookie: client side "sl@exabyte" <sb5309@hotmail.com> - 2011-11-03 17:10 +0800
  Re: session cookie: client side Balazs Nadasdi <yitsushi@gmail.com> - 2011-11-03 05:23 -0700
    Re: session cookie: client side "sl@exabyte" <ecp_gen@my-rialto.com> - 2011-11-04 14:14 +0800
      Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 07:55 -0400
        Re: session cookie: client side "sl@exabyte" <sb5309@hotmail.com> - 2011-11-04 22:21 +0800
          Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 14:40 -0400
        Re: session cookie: client side Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-04 15:53 +0000
          Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 14:41 -0400
      Re: session cookie: client side Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-04 15:52 +0000

csiph-web