Re: [xml-dev] Re: Cookies at XML Europe 2004 -- Call for Participation

From
John Cowan <>
To
Joshua Allen <>
Date
2004-01-08T00:01:26Z
ID
<>
Thread
Re: [xml-dev] Re: Cookies at XML Europe 2004 -- Call for Participation
Joshua Allen scripsit:

> Regardless of whether you store your session token as Rich describes
> in a cookie, or in the URL, there is a danger that someone could use
> a man in the middle attack like you describe.  

Indeed, if I get to filter *all* your accesses to the net, I can make
you believe anything I want, by masquerading as all possible trusted
third parties.  There's nothing to be done about this.

-- 
Do NOT stray from the path!             John Cowan <>
        --Gandalf                       http://www.ccil.org/~cowan