Re: Secure cookies survey

David W. Morris (dwm@xpasc.com)
Thu, 20 Mar 1997 09:39:00 -0800 (PST)


On Thu, 20 Mar 1997, Dave Kristol wrote:

> Here's an inexact application survey:
> 
> Does anyone use, or know of an application that uses, cookies that are
> labeled "Secure"?
> 
> If not, I will consider simply removing "Secure" from the cookie spec.

I know an application which is quite likely to want the unsecure
implication of secure ... that is, set the cookie in a secure response and
have it returned in a non-secure transaction. The application is still in
the prototype phase.

Dave Morris