Defeat Exit Node Sniffing?

coderman coderman at gmail.com
Thu Mar 6 00:58:35 UTC 2008


On Wed, Mar 5, 2008 at 4:34 PM, scar <scar at drigon.com> wrote:
> ...
>  there was no bug in the add-on; i saw the change to the cookie take
>  place.  it is a problem with the website/webmaster.

the modification (secure only = true) must be made with every updated
expiration / set cookie received, otherwise a session refresh / save
will save without the secure only option enforced.

it might be easiest to extend the existing modify headers extension to
alter incoming cookie parameters...  (and if you find out, document in
the wiki :)



More information about the tor-talk mailing list