<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Token etc. is sent to any webserver - security issue? in ArcGIS Online Questions</title>
    <link>https://community.esri.com/t5/arcgis-online-questions/token-etc-is-sent-to-any-webserver-security-issue/m-p/280012#M13912</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hans,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for bringing up this issue. This has been logged as a bug which you can find on the support services site: &lt;A href="http://support.esri.com/bugs/nimbus/QlVHLTAwMDA5NjYzOQ==" title="http://support.esri.com/bugs/nimbus/QlVHLTAwMDA5NjYzOQ=="&gt;BUG-000096639: Esri authorization cookies are included in requests ..&amp;nbsp; &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can contact your support organization to be attached to the bug for tracking purposes. If you have security concerns in the future, I want to encourage you to log them on our trust.arcgis.com site:&amp;nbsp; &lt;A href="http://doc.arcgis.com/EN/TRUST/SECURITY-CONCERN/" title="http://doc.arcgis.com/EN/TRUST/SECURITY-CONCERN/"&gt;Report a Security Concern | ArcGIS&lt;/A&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Jun 2016 18:39:12 GMT</pubDate>
    <dc:creator>KellyGerrow</dc:creator>
    <dc:date>2016-06-09T18:39:12Z</dc:date>
    <item>
      <title>Token etc. is sent to any webserver - security issue?</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/token-etc-is-sent-to-any-webserver-security-issue/m-p/280010#M13910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just registered to ArcGIS Online to build my own map by adding Web Services. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when I do that, my ArcGIS-Online Cookie which contains my username, my token, my accountId, my role, my region, my culture etc. is send via REST to that URL I connect to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this makes all the accounts pretty insecure. Or not? What do you think?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 May 2016 13:42:04 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/token-etc-is-sent-to-any-webserver-security-issue/m-p/280010#M13910</guid>
      <dc:creator>HansDampf</dc:creator>
      <dc:date>2016-05-13T13:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Token etc. is sent to any webserver - security issue?</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/token-etc-is-sent-to-any-webserver-security-issue/m-p/280011#M13911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately there are no comments to this topic. Maybe I explain a bit more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In ArcGIS Online it's possible to connect to web service like ArcGIS Services or OGC WMS. These Services can be hosted anywhere in the world, on servers there. I discovered that ArcGIS Online sends an only for ArcGIS-Online relevant cookie with user information to the host Server of the&amp;nbsp; Service (WMS etc.). Why does any server in the world needs my ArcGIS Online user credentials? This can`t be right&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The thing is that some map service servers block cookies, because the absolutely don't need them. But ArcGIS Online can't connect to a map service if the cookie is blocked, a cookie only containing ArcGIS Online User Information, on a Server somewhere in the world ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope someone at ESRI is concerned about this and their users' information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2016 14:49:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/token-etc-is-sent-to-any-webserver-security-issue/m-p/280011#M13911</guid>
      <dc:creator>HansDampf</dc:creator>
      <dc:date>2016-06-08T14:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Token etc. is sent to any webserver - security issue?</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/token-etc-is-sent-to-any-webserver-security-issue/m-p/280012#M13912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hans,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for bringing up this issue. This has been logged as a bug which you can find on the support services site: &lt;A href="http://support.esri.com/bugs/nimbus/QlVHLTAwMDA5NjYzOQ==" title="http://support.esri.com/bugs/nimbus/QlVHLTAwMDA5NjYzOQ=="&gt;BUG-000096639: Esri authorization cookies are included in requests ..&amp;nbsp; &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can contact your support organization to be attached to the bug for tracking purposes. If you have security concerns in the future, I want to encourage you to log them on our trust.arcgis.com site:&amp;nbsp; &lt;A href="http://doc.arcgis.com/EN/TRUST/SECURITY-CONCERN/" title="http://doc.arcgis.com/EN/TRUST/SECURITY-CONCERN/"&gt;Report a Security Concern | ArcGIS&lt;/A&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2016 18:39:12 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/token-etc-is-sent-to-any-webserver-security-issue/m-p/280012#M13912</guid>
      <dc:creator>KellyGerrow</dc:creator>
      <dc:date>2016-06-09T18:39:12Z</dc:date>
    </item>
  </channel>
</rss>

