|
Posted by howa on 06/13/07 15:57
On Jun 13, 11:44 pm, Jerry Stuckle <jstuck...@attglobal.net> wrote:
> Ajax requires javascript be enabled. And in a small corporation with a
> single firewall/proxy, all users will have the same ip address.
>
> IP addresses are not reliable at any time other than when responding to
> the immediate request.
>
yes, IP should not be used. I agree
back to the corporation example, if SSL can't be used, what are the
best practices for protecting session cookie?
Seems there is no 100% safe solution - if people can capture your
request and can reproduce them!
[Back to original message]
|