Quoting Hans Lellelid <hans at appliedsec.com>:

> I was wondering if there's any reference material on Horde & security --
> particularly sessions.

Nothing specific, really.

> I was thinking that there would be security
> advantages to disabling cookies for my application.  What's the thinking
> behind the cookies being more secure than session IDs in the URL?

URLs are logged much more often. And if you're using SSL, then cookies are
encrypted, while it's much easier to intercept the requested URL somewhere -
a proxy if it's used for SSL, log files, etc. etc.

> (Is the main issue session hijacking possibilities when cookies are
> disabled?)



