So in the recent past, i took a horrifying look at browser sessions, and i came to a horrific conclusion, as it turns out, browser sessions are completely and utterly broken. You can read, write, modify, change, tack on to sessions as you please, and the worst part is that it is completely transparent and if it fails, it feels normal, and if it succeeded, i stole your session... If i have 2 ssh sessions open into two ssh boxes, there is no way for one of the boxes to hack the other box, because session management in ssh is really good, however if i have one website open in one tab, and another one open in another tab, can one website hack the other? ABSOLUTELY!!!!


Session management on the web is entirely broken, look at it if you wonder how specifically, my question to you is, how can we go about fixing them? Now less discuss ^_^

