| Article: |
Cookie Specification Vulnerabilities | |
| Subject: | What About RFC 2965? | |
| Date: | 2004-05-12 23:26:57 | |
| From: | Morxy | |
Alexander faults the Netscape Cookie Specification (NCS) and then hopes a new, improved specification will emerge. But what about RFC 2109 (Feb 1997) and RFC 2965 (Oct 2000). These both suggest cookie improvements, with new HTTP headers (Set-Cookie2), a different way of specifying lifespan (Max-Age in seconds rather than an absolute date with Expires) and a protocol by which servers can revoke cookies they'd earlier left with clients.
|
||
Women in Technology
Hear us Roar
