How to encrypt session id in cookie?

后端 未结 8 1519
春和景丽
春和景丽 2021-02-06 05:43

While I was reading about session hijacking articles, i learned that it would be nice to encrypt session id value that is stored in a cookie.

As far as I know, when I s

8条回答
  •  既然无缘
    2021-02-06 06:16

    It makes sense to encrypt cookie data when you use cookies to store sensitive info. that only the server should read (decrypt).

    There's no reason to encrypt session id, since the hacker can use that encrypted session id to impersonate his victim.

提交回复
热议问题