You are here |
sriku.org | ||
| | | |
educatedguesswork.org
|
|
| | | | ||
| | | |
palant.info
|
|
| | | | Allowing password-based authentication without letting the server know the password is fascinating. Unfortunately, for web applications this doesn't solve any problems. | |
| | | |
blog.plataformatec.com.br
|
|
| | | | A security bug (CVE-2015-8314) has been reported in Devise's remember me system. Devise implements the "Remember me" functionality by using cookies. While this functionality works across multiple devices, Devise ended-up generating the same cookie for all devices. Consequently, if a malicious user was able to steal a remember me cookie, the cookie could be used | |
| | | |
idiallo.com
|
|
| | Downloading things from an official source can cost you lots of time and money in the long run |