It depends. If the site is using a cookie, then it can get pretty much any info it wants...
In typical end-user/browser usage, TLS authentication is unilateral: only the server is authenticated (the client knows the server's identity), but not vice versa (the client remains unauthenticated or anonynmous).
P.S - SSL is now TLS.
No comments:
Post a Comment