By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Improperly Stored Session Cookies – What the crates.io Team Is Doing to Fix It | HackerNoon
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Improperly Stored Session Cookies – What the crates.io Team Is Doing to Fix It | HackerNoon
Computing

Improperly Stored Session Cookies – What the crates.io Team Is Doing to Fix It | HackerNoon

News Room
Last updated: 2025/05/03 at 7:59 AM
News Room Published 3 May 2025
Share
SHARE

Today the crates.io team discovered that the contents of the cargo_session cookie were being persisted to our error monitoring service, Sentry, as part of event payloads sent when an error occurs in the crates.io backend. The value of this cookie is a signed value that identifies the currently logged in user, and therefore these cookie values could be used to impersonate any logged in user.

Sentry access is limited to a trusted subset of the crates.io team, Rust infrastructure team, and the crates.io on-call rotation team, who already have access to the production environment of crates.io. There is no evidence that these values were ever accessed or used.

Nevertheless, out of an abundance of caution, we have taken these actions today:

  1. We have merged and deployed a change to redact all cookie values from all Sentry events.
  2. We have invalidated all logged in sessions, thus making the cookies stored in Sentry useless. In effect, this means that every crates.io user has been logged out of their browser session(s).

Note that API tokens are not affected by this: they are transmitted using the Authorization HTTP header, and were already properly redacted before events were stored in Sentry. All existing API tokens will continue to work.

We apologise for the inconvenience. If you have any further questions, please contact us on Zulip or GitHub.


Adam Harvey on behalf of the crates.io team

Also published here

Feature image: https://unsplash.com/photos/baked-cookies-ZS3OfU40CQU

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Don’t upgrade to T-Mobile Experience; your legacy plan is likely better
Next Article Our favorite expert-tested TV brands include LG, TCL, Hisense, and Samsung
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Beloved mall staple confirms launch of brand new ‘bold’ store format
News
Here’s what’s coming to macOS Tahoe | News
News
Qubic Just Mined Monero And Redefined What Proof Of Work Can Be | HackerNoon
Computing
Major channel replaced on millions of Sky Q boxes TODAY plus three more changes
News

You Might also Like

Computing

Qubic Just Mined Monero And Redefined What Proof Of Work Can Be | HackerNoon

4 Min Read
Computing

China’s AI agent Manus gains traction amid growing demand for autonomous AI · TechNode

3 Min Read
Computing

12 Best Influencer Marketing Platforms & Tools in 2025

7 Min Read
Computing

The Top 10 Online Learning Platforms for 2025

24 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?