Comment on Securing the Rails session secretparentComments−tptacek13yMake sure your session secret is a long random string (it might be tempting, if you're passing it in through the environment, to make it shorter or readable). It's an HMAC key that anyone who can get a session from your application can dictionary.−MattRogish13yOh yes. It's probably ridiculously long (I think 256 chars, letters numbers special etc) :)
Comments
Make sure your session secret is a long random string (it might be tempting, if you're passing it in through the environment, to make it shorter or readable). It's an HMAC key that anyone who can get a session from your application can dictionary.
Oh yes. It's probably ridiculously long (I think 256 chars, letters numbers special etc) :)