The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
From: DHH <david.heineme...@gmail.com>
Date: Wed, 21 Nov 2007 07:11:24 -0800 (PST)
Local: Wed, Nov 21 2007 10:11 am
Subject: Re: Don't make cookie-stored sessions a default
> > Let's not confuse secrecy with security. Session cookies typically
Yes.
> > store a user_id and a flash message. We only need to ensure that the > > user_id is not changed, and hmac-sha1 provides that beautifully. This > > is not by any stretch insecure. > Just to be absolutely clear, you can feel comfortable using session
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||