smullis has asked for the wisdom of the Perl Monks concerning the following question:
You guys seem like you know your onions...
Can I ask for a quick sanity check on an idea?
Background -
I'm not convinced that this is safe from cookie poisoning (the values of some of the keys would be easy to guess). Also, I would like the mod_perl app to be flexible enough to react to any combination of values with which it is presented (i.e. for values that do not yet exist).
I am thinking that if the ASP system digitally signed the values in the cookie (using its private key) then the mod_perl app could be sure that they originated there and only there and act accordingly.
Is this a valid approach?
Many thanks in advance and apologies for the not-directly-perl-related nature of this post.
SM
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: [OT?] Sanity check... (On MD5, 3DES, Cookies and other animals)
by perrin (Chancellor) on Nov 05, 2004 at 18:28 UTC | |
|
Re: [OT?] Sanity check... (On MD5, 3DES, Cookies and other animals)
by hardburn (Abbot) on Nov 05, 2004 at 17:31 UTC | |
by smullis (Pilgrim) on Nov 05, 2004 at 17:58 UTC | |
by waswas-fng (Curate) on Nov 05, 2004 at 20:51 UTC | |
by smullis (Pilgrim) on Nov 05, 2004 at 20:58 UTC | |
by hardburn (Abbot) on Nov 05, 2004 at 18:46 UTC | |
by smullis (Pilgrim) on Nov 05, 2004 at 20:55 UTC |