Also, doesn't cryptographically signing (or fully encrypting, in Rails 4) the cookie just add more time to processing than using a database? I always assumed cryptography is slower than IO
Also, doesn't cryptographically signing (or fully encrypting, in Rails 4) the cookie just add more time to processing than using a database? I always assumed cryptography is slower than IO
Cryptography is a CPU-bound operation that often has specialized hardware support. Here's a rule of thumb: in modern computing, IO incurs a greater cost than pretty much anything you can do locally on-CPU. IO is incredibly expensive: cryptography, not so much. If you pipeline your crypto operations and disk fetches, you won't increase response latency at all.
[1] http://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
Useful link: http://jamescrisp.org/2013/08/04/moving-to-https-rails-force...
It's as simple as that. Never assume that anything transmitted over HTTP is safe, because that assumption will come back to bite you.
Are you suggesting not using SSL?
If not, can you clarify your point?
Thanks.