Re: [xml-dev] Re: Cookies at XML Europe 2004 -- Call for Participation

From
Elliotte Rusty Harold <>
To
Rich Salz <>
Date
2004-01-09T04:52:48Z
ID
<p06010210bc23e3a62879@[192.168.254.4]>
Thread
Re: [xml-dev] Re: Cookies at XML Europe 2004 -- Call for Participation
At 9:54 PM -0500 1/8/04, Rich Salz wrote:


>>  I don't see any equivalent action a
>>  client can take to protect themself against a cookie based attack.
>
>Make sure they always connect to the site with SSL.

No, the client can't choose that. The server has to make it 
available. If the server doesn't provide SSL access, there's nothing 
the client can do to enable SSL short of not connecting to the site. 
:-(
-- 

   Elliotte Rusty Harold
   
   Effective XML (Addison-Wesley, 2003)
   http://www.cafeconleche.org/books/effectivexml
   http://www.amazon.com/exec/obidos/ISBN%3D0321150406/ref%3Dnosim/cafeaulaitA