tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Endre StĂžlsvik <>
Subject Re: Session creation speed
Date Tue, 23 Jan 2001 12:00:58 GMT
On Tue, 23 Jan 2001, Steve Smale wrote:

| Thanks for that, its steaming along at a good ol' speed now!
| What is to gain by using the secure random generator?

I guess it's more secure?! It initializes a better random number
generator, which isn't that predictable. If you can predict a session
cookie, you don't have any client security anymore. Another person can
supply that id, and place an order or whatever as that user.

It's only the first hit after a restart that gets the problem. Just try to
make a new session (with another browser), and you'll see that it's not
slow anymore.


View raw message