Advice on when to use SSL? esp. Session ID security

From: Luke Arms (linarms@yahoo.com)
Date: 04/04/03


From: Luke Arms <linarms@yahoo.com>
Date: Fri, 04 Apr 2003 04:20:02 GMT


Hi,

I'm just trying to assess when/how much to use SSL encryption on an ASP.NET
site. Obviously I'll be using it on the login page, but what do people
think about retaining SSL for the duration of the user's session? My
primary concern is that although 'crackers' might be unable to get a
username/password, they could possibly forge a session cookie after the
user logs on and returns to a standard HTTP connection. To what extent
should this be a genuine concern? Given the overhead of running an entire
site over SSL if a user's logged on, it would be preferable to only use
HTTPS for the login page ...

Any comments?

Thanks,

Luke



Relevant Pages

  • Re: SSL php code
    ... > Sean I am planning on exclusievely using secure pages (ssl) after the user requests to login. ... This will securely redirect to a login ...
    (comp.lang.php)
  • Re: Advice on when to use SSL? esp. Session ID security
    ... round trip (I believe this is what IIS does for its own session identifier). ... Obviously I'll be using it on the login page, ... > think about retaining SSL for the duration of the user's session? ... > user logs on and returns to a standard HTTP connection. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: sendmail with smtp relay authentication
    ... LOGIN PLAIN')dnl ... the mail log and also attached the auto mail response I got. ... m31N0w2T002913: return to sender: User unknown ... 505 5.0.0 Message is sent with SSL but SSL is not allowed ...
    (comp.mail.sendmail)
  • RE: Authorize.Net Plain Text Login Transmission
    ... service provider to find out personally whether or not they are vulnerable. ... Authorize.Net Plain Text Login Transmission ... > function as if you had gone to the correct SSL version of the page. ...
    (Bugtraq)
  • Re: Google Secure Access
    ... >> email INCLUDING CLICKING ON THAT LITTLE SSL OPTION. ... Google then SENDS YOUR LOGIN DETAILS IN THE CLEAR TO YOUR ISP. ...
    (sci.crypt)