Are passwords stored in cookies?

余生颓废 提交于 2019-12-04 13:47:23

问题


Looking at gmail and facebook I was wondering where do they store your password and account info when you log off and you have the function "Keep me signed in" on.

I know they store it in cookies but isnt this hackable/stealable? How safe is this system and where is this information stored?


回答1:


What they save is a unique session ID that is essentially a randomly generated string. With that session ID they can store your state on the backend, i.e. logged in or not. They never store your password, encrypted or not, in a cookie.



来源:https://stackoverflow.com/questions/12990557/are-passwords-stored-in-cookies

标签
易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!