19 Aug
SSLification
I saw this on Slashdot today, where a bunch of hackers developed a tool for stealing session IDs in Gmail. By default, gmail authentication is encrypted, but the rest of your session is not. In the requests that you send to gmail is included a session ID cookie, which is in the clear. With your [...]


