in reply to Re^7: Is this a secure way to prevent cookie tampering
in thread Is this a secure way to prevent cookie tampering
Compress before encryption means to doing the compression before encryption, because doing afterwards is useless since ciphertext is uncompressable. It does not mean you have to use compression. Compression does provide some benefit by hiding the plaintext a little bit. Since cookies are so small, compression isn't all that useful.
I would say encrypting sensitive information in the cookie is silly. Either the info is sensitive, and shouldn't be put in a cookie, or it isn't and can be plaintext. For most applications, authentication is more important than hiding secrets. For example, a cookie that contains a username for authentication, leaking the username to eavesdroppers is a privacy problem. Allowing someone to tamper with or replay the cookie is a major breach.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^9: Is this a secure way to prevent cookie tampering
by exussum0 (Vicar) on Jul 01, 2004 at 16:44 UTC |