[cap-talk] Security considerations for cookies

Sandro Magi naasking at higherlogics.com
Tue Feb 23 11:16:01 PST 2010


On 23/02/2010 3:58 AM, Toby Murray wrote:>> I agree, but gmail already
sports a solution: require the user to pick a
>> custom theme, colour scheme, or a unique icon for his webmail interface,
> 
> I use the standard default for all. I'm sure the vast majority of
> users do likewise. I'm not convinced that this would offer any real
> protection, therefore.

Hence why I said the user would be required to pick one, and the order
of selections presented would always be randomized.

Sandro



More information about the cap-talk mailing list