Great Circle Associates Firewalls
(December 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: caching protected documents
From: Davide Migliavacca <Davide . Migliavacca @ inferentia . it>
Date: Thu, 21 Dec 1995 11:04:15 +-100
To: "'firewalls @ greatcircle . com'" <firewalls @ greatcircle . com>
Posted-date: Thu, 21 Dec 1995 10:52:18 +0100

It is true that browsers (not only Netscape!) normally don't request a user/password to access a page once they had it in the same session.
While this is a problem if you leave your machine with the browser loaded after having accessed that page, I think this is an _attitude_ problem.
I would never leave my machine logged in to _anything_ in the first place (use a password-protected screen saver if you want to spare the extra shutdown/startup time when you leave).

But there is a WORST problem with Netscape up to version 2.0b3.

The browser let you access a protected page even across sessions!
Just fiddle a little with the password dialog, do a cancel at the right moment, and you'll have access to the cached copy of the document (servers are smarter than this) even though you have _NOT_ correctly authenticated.

This seems to be a known problem repeatedly reported. AFAIK, no answer has come from Netscape as of now, at least on the publicly visible tech notes and newsgroups.

Maybe because nobody is really believing in WWW "authentication" now :-)





----------------------------------------
Davide Migliavacca - Inferentia (Milano, IT)
Phone +39 (2) 59928.1 FAX .221
*** opinions above are (you guess!) mine ***
----------------------------------------


Indexed By Date Previous: Architecture question
From: Laurent Balzinger - Centre Reseau Communication - Universite Louis Pasteur <Laurent . Balzinger @ crc . u-strasbg . fr>
Next: firewalls testing
From: Bruno Otto Theodoro Rosa <brosa @ ifqsc . sc . usp . br>
Indexed By Thread Previous: Architecture question
From: Laurent Balzinger - Centre Reseau Communication - Universite Louis Pasteur <Laurent . Balzinger @ crc . u-strasbg . fr>
Next: Firewalls-Digest V4 #719 -Reply
From: brogers <BROGERS @ STATE . MI . US>

Google
 
Search Internet Search www.greatcircle.com