Forum Discussion
Persistence Cookie Random Values
If the persistence cookie is set up to be encrypted, then a random IV is used to do the encryption. (The IV is included in the base-64 encrypted result, allowing it to be decrypted again.) This means that the same unencrypted cookie can encrypt to many different results as the IVs can differ.
The reason for this is so that different clients of the website will get different persistence cookies. Cookies cannot be compared to determine any information about what the cookie originally was. (A simpler scheme would encrypt identical cookies to the same encrypted result. This would allow two users to see if they got the same encrypted = same unencrypted cookie, which would be a small information leak.)
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com