HOWTO – Protect GMail from session snatching
By default, Google Mail sets a session cookie that doesn’t have the secure flag, meaning that if you log in to GMail, leave, and later return to the unencrypted “http://” URL (instead of “https://”), your browser will transmit your session information in plain-text to the server. This problem gained some attention last year and we […]