From: "Ed Finkler" <funkat...@gmail.com>
Date: Wed, 7 May 2008 20:58:56 -0400
Local: Wed, May 7 2008 8:58 pm
Subject: Re: Sending encoded login details to API
On Wed, May 7, 2008 at 6:16 PM, Benjamin Tucker <btuc...@gmail.com> wrote: If *any* server is rooted, the attacker can do *whatever they want.* > Hey Dean, > I'm the guy that wrote http://stream.btucker.org/post/33710515 > Your solution sounds like an improvement, but not ideal. Now if your Stealing data out of session caches is the least of your problems. SSL is a good idea, yes, but you should *not* be storing this data in I'll repeat what I stated before: authentication data should *never* -- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||