Gmail/SSL

coderman coderman at gmail.com
Tue Mar 11 01:47:14 UTC 2008


On Mon, Mar 10, 2008 at 5:37 PM, coderman <coderman at gmail.com> wrote:
> ...
>  managing this on your end transparently makes it impossible to
>  exploit.

i am referring solely to the auth cookie management here; host and
browser vulnerabilities that bypass SSL/TLS protections are an
entirely different problem...

regarding the modification of cookie parameters via browser plugin,
"Modify Headers" [0] might be a close fit needing only a few tweaks to
implement secure only.

0. https://addons.mozilla.org/en-US/firefox/addon/967



More information about the tor-talk mailing list