Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

so now it is only a matter of time until the keylogging software that everyone is so terrified of is modified to also take the session cookie from your browser that authenticates you to gmail. you know, the thing that makes it okay for you to click "remember this computer for 30 days" ...


The session cookies are often tied to IP address.


are they? have you ever logged in at home, suspended, and then gone to work? or the coffee shop?


Google might compare browser/OS entropy as well as IPs.

https://www.eff.org/deeplinks/2010/01/primer-information-the...


Like FireSheep already did?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: