Comment 16 for bug 46591

Revision history for this message
Matthew Paul Thomas (mpt) wrote :

http://fscked.org/category/tags/defcon includes articles on how sites with HTTPS login and HTTP everything-else are vulnerable to session stealing, and how to prevent it.