Security in sinatra with Rack :: Session :: EncryptedCookie

Viewed 48

Currently I use Rack: Session: Pool in sinatra but I need to switch to Rack :: Session :: EncryptedCookie in order to increase concurrency.

Before modifying my code I would like to know how safe it is to save the whole session with Rack :: Session :: EncryptedCookie

I understand that the user's identification data is cryptographically signed but I see that the rack_session variable is encrypted in the browser and available to the user.

I want to know if a person with the necessary knowledge can decrypt that hash on the user's side and get to obtain its structure to enter the site as if it were another user.

0 Answers
Related