|
|
|
|
|
by patmcc
966 days ago
|
|
>>>If someone steals this cookie, they can impersonate you. Right; but with WebSession, if someone steals the client keypair (and generated shared secret), they can impersonate you just as easily. Why would this be any more secure against that? Cookies aren't perfect, for sure, but I don't think this solves it. |
|