in reply to Re: Secure Login
in thread Secure Login

Making the cookie content more opaque wouldn't help. Snooping an opaque cookie is just as simple as snooping the login details or the plaintext cookie.

Moving to an expiring key based authentication system with a secure login would reduce the window of opportunity for highjacking. Encrypting everything over https makes it more secure (if, of course, you trust the gods and pmdev).

However, personally, for something like perlmonks I really don't think it's worth the effort or cost.