tenderlove mentions it has been assigned CVE-2012-5664. This is that CVE:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5664
It references two articles that require session secrets.
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5664
It references two articles that require session secrets.
EDIT Well... he might, but I've never seen him do it. He's a security professional, after all.
(I wouldn't have said it was possible unless I had a curl line that did it, for what it's worth.)