-
January 16"You'll see the typical security geek saying, 'People are dumb, people are stupid, they're never going to be trained,'." said Rohyt Belani, PhishMe co-founder and CEO. "We have statistics to prove otherwise." PhishMe Twitter
- Zappos customers, make sure you look out for phishing emails: http://t.co/xcavPbOs 03:51:21 PM January 26, 2012 from CoTweet ReplyRetweetFavorite
- The importance of educating users to spot potential attacks is talked about in article about DoD ID card attack: http://t.co/jRnL7AXB 04:06:34 PM January 18, 2012 from CoTweet ReplyRetweetFavorite
Blogroll
Links
Archives
|






Great find Corey! Maybe it's not too late for this to be reconsidered.
[...] OWASP conference proved to be a great ground to bring up this topic of the proposed Rails 2.0 cookie storage [...]
Please see my comment on Part II debunking the claim of brute-force attack.
Sorry, updated the link for “cookie_store.rb” which did take you to an older version of the file. Brute forcing the HMAC is still possible. I'm sure there are cases where this type of session storage would make sense, but from a security stand point, it makes me nervous that this will be the default storage option.