Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 205231
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 11, 20262026-05-11T17:32:17+00:00 2026-05-11T17:32:17+00:00

Q1 I’ve read that when setting the timeout of an authentication cookie, we should

  • 0

Q1
I’ve read that when setting the timeout of an authentication cookie, we should keep in mind that the longer the cookie persists, the greater the chance of a cookie being stolen and misused.

A) But assuming we secure our application against replay attacks by enabling SSL for the entire application, and since forms authentication module also encrypts authentication data in authentication cookie, then I would think there is no chance of this cookie being misused and thus cookies being persisted for longer periods of time should not present any security risks?!

Q2

FormsAuthentication.FormsCookiePath specifies where authentication cookie is stored. Default value is ‘/’.

A) Assuming default value ’/’ is used, where is cookie saved then?

B) Is this option only used for persistent cookies?

thanx

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-11T17:32:17+00:00Added an answer on May 11, 2026 at 5:32 pm

    2A The cookie path is the path on the server the cookie relates to, not the path where the cookie is store.

    From http://www.quirksmode.org/js/cookies.html

    The path gives you the chance to specify a directory where the cookie is active. So if you want the cookie to be only sent to pages in the directory cgi-bin, set the path to /cgi-bin. Usually the path is set to /, which means the cookie is valid throughout the entire domain.
    This script does so, so the cookies you can set on this page will be sent to any page in the http://www.quirksmode.org domain (though only this page has a script that searches for the cookies and does something with them).

    You are using ASP.Net. Also see the “CookieLess” Session and Authenication options e.g.
    http://msdn.microsoft.com/en-us/library/system.web.security.formsauthentication.formscookiepath.aspx If you are worried about cookies. This uses a URL session ID instead to track your session.

    You can also use a SQL Server to track session state or a State server.
    e.g.

    <sessionState mode="SQLServer" sqlConnectionString="SQLSessionDB" cookieless="false" timeout="65" cookieName="MSESSID"/>
    

    1A. SSL encrypts transport. Hence your cookies will be less likely to be stolen on route to the client or back. That doesn’t mean a malicious program on the client computer can’t steal it. This is very unlikely though.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Ask A Question

Stats

  • Questions 95k
  • Answers 95k
  • Best Answers 0
  • User 1
  • Popular
  • Answers
  • Editorial Team

    How to approach applying for a job at a company ...

    • 7 Answers
  • Editorial Team

    How to handle personal stress caused by utterly incompetent and ...

    • 5 Answers
  • Editorial Team

    What is a programmer’s life like?

    • 5 Answers
  • Editorial Team
    Editorial Team added an answer I’d use a do-while loop: do { $newKey = makeKey();… May 11, 2026 at 6:56 pm
  • Editorial Team
    Editorial Team added an answer It depends on what you want. Since the class is… May 11, 2026 at 6:56 pm
  • Editorial Team
    Editorial Team added an answer You can either return an object that has multiple error… May 11, 2026 at 6:56 pm

Related Questions

What is the difference between the Project and SVN workingDirectory Config Blocks in CruiseControl.NET?
Problem: how to provide a distributed, scalable and disaster resistant pub/sub service with WCF.
A) Question below is based on the assumption that controls are always binded to
I am trying to generate a report by querying 2 databases (Sybase) in classic
I'm looking at adding Visual Studio Database Edition (aka. VSDE) to my version of

Trending Tags

analytics british company computer developers django employee employer english facebook french google interview javascript language life php programmer programs salary

Top Members

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.