There are three types of computer cookies: session, persistent, and third-party. These virtually invisible text files are all very different. Each with their own mission, these cookies are made to track, collect, and store any data that companies request.
They say Cookies are bad. I personally believe there should be a "smarter" way to detect the state of a user on a web app.
Say, currently this is how it works in a distributed environment where xyz.com has many pools and servers (which i know of):
So, feature1 blindly trusts the client due to the cookie dropped by login module.
But I feel a fundamental flaw here at stage 3. What if a hacker clones a cookie and tries to do something? (which is the first obvious thing a hacker will try to do, cookie sniffing)
So, is there any alternative to this? - how will web storage, flash stored objects do in future? or cookies will rule?
Not looking for an obvious answer, because there are none. I am interested in different viewpoints of approaching this probem.
Thanks
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With