[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

RE: Re: Cookies at XML Europe 2004 -- Call for Particip atio


cookie location header
> Note that the password is *not* transmitted in the URL. The server
> requests the password using standard HTTP authentication mechanisms
> and the client provides it in the standard way.

Then my requirement of limited exposure isn't met.  Even worse, if *any*
packet is stolen, then my password is exposed.  The only way to prevent
this is to use SSL for all traffic, which is not always a feasible,
or even reasonable, trade-off.

> Similarly other
> information that is often stored in cookies--shopping cart contents,
> path through a site, time of login, etc.--also need not be stored in
> the URL. The server maintains this information as it does even with
> cookies, at least in a secure system) and displays it to the user in
> the content of the page. However, it need not show up in referrer
> logs, browser location bars, and other such insecure places.

I don't understand how you could do this.  Can you explain?  The
client doesn't need the time of login, the server does.  I don't see
what is the point of putting it in a clickable URL that the client could
fetch.  Who cares if the client ever fetches it?

>  But for each
> different resource, there should be at least one URI. Cookie based
> sites fail this test.

Only on those sites that use cookies wrong.  I assume you mean the
kind of site that never changes the URL in the location bar, but
instead stuffs the "real" URL in the cookie and returns a bogus
Location header or some such.  That's bad and broken.  It indicates
that the site is doing things wrong, not that cookies are wrong.

        /r$

--
Rich Salz                  Chief Security Architect
DataPower Technology       http://www.datapower.com
XS40 XML Security Gateway  http://www.datapower.com/products/xs40.html
XML Security Overview      http://www.datapower.com/xmldev/xmlsecurity.html


PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
 

Stylus Studio has published XML-DEV in RSS and ATOM formats, enabling users to easily subcribe to the list from their preferred news reader application.


Stylus Studio Sponsored Links are added links designed to provide related and additional information to the visitors of this website. they were not included by the author in the initial post. To view the content without the Sponsor Links please click here.

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.