Hacker News new | ask | show | jobs
by account42 964 days ago
> Even with all of these, a compromised client, an unsecured application log, or an eavesdropper on the connection after TLS termination could result in a cookie being stolen.

So it can be stolen from the client or the server. Same applies to this proposal.