Hacker News new | past | comments | ask | show | jobs | submit login

I completely agree with this and have just released a session-cache for python that completely ignores encryption and just stores uuid in a cookie, and relies on server side lookups for session work.



Make sure you are using HTTPS exclusively so you aren't vulnerable to Firesheep-style attacks.


That's in the docs :-)

Ooops no it's not - kind of assumed it was obvious - thank you for the reminder :-)


That's in the docs :-)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: