Pivotal Labs

Main menu

Skip to primary content
Skip to secondary content
  • About
  • Case Studies
  • Team
    • Executives
    • Locations
      • San Francisco (HQ)
      • Boston
      • Boulder
      • Denver
      • London
      • Los Angeles
      • New York
  • Community
    • Blogs
    • Tech Talks
    • Events
  • Careers
    • Lifestyle
    • Principles & Practices
    • Benefits
    • FAQ
    • Apply
  • Contact
    • Press Room
    • Press Releases
    • In The News
    • Press Kit
  • All
  • Labs
  • Standup
  • Tracker

Tracker going all HTTPS

Dan Podsedly
Tuesday, May 24, 2011

About six months ago, a certain Firefox extension made headlines by making it incredibly easy for people to intercept insecure web cookies and access private information on major web sites such as Facebook, as well as Pivotal Tracker.

In response, we made session-wide HTTPS enabled by default, but made it possible to disable it on your profile. We also left the option to force HTTPS only access for specific projects.

This partial HTTPS approach required us to use a somewhat complicated secure cookie scheme to prevent secure session hijacking (aka “sidejacking“). While this did close the door to this particular attack vector, it introduced some session instability, especially in Safari, due to intermittent dropping of secure cookies. Also, full HTTPS is generally considered to be more secure.

In next week’s release, Tracker is going all HTTPS. The static front pages will remain non-HTTPS by default, but all internal pages, for example the dashboard and project pages, will now be HTTPS-only. This will make Tracker more secure, and it allows us to remove the extra cookies related to session hijacking prevention, which should help with unintentional browser session expiration.

In addition, we’re improving how the “remember me” option works – it will now allow you to stay signed in for 2 weeks in multiple browsers.

Note: You will continue to be able to use the API via plain HTTP, unless the project you’re accessing has the “Use HTTPS” option set.

  • 0 Shares
  • Share on Facebook
  • Share on Twitter

One comment

  1. Rob Zolkos says:

    Awesome! Especially the Remember Me functionality :)

    May 24, 2011 at 7:21 pm

Add New Comment Cancel reply

Your email address will not be published.

Dan Podsedly

Dan Podsedly

Dan Podsedly manages Pivotal Tracker, Pivotal Labs’ award winning project management and collaboration software.

Dan has been building large applications since the Smalltalk era, and has been a practitioner and coach of agile programming methods since the earliest days of Extreme Programming. He has led projects in a variety of industries, built a consulting practice from the ground up, and was instrumental in the successful adoption of agile methods at some of the world's largest e-commerce companies.

Dan joined Pivotal in 2004 as Principal, and spent the next four years leading Pivotal’s largest client engagements. In 2008, Dan led the public launch of Pivotal Tracker, originally developed as an internal tool to help Pivotal developers improve their efficiency, and has grown the product into what it is today - a popular, well known force of agile transformation in the software industry used by hundreds of thousands of developers.

Dan's Blog

Recent Posts

  • Monday’s Tracker Outage, New Status Page
  • Browser support in Pivotal Tracker
  • 2013 Tracker Update – New Features, New API, New Design
Subscribe to Dan's Feed

Author Topics

agile (39)
api (4)
productivity (13)
ios (2)
ipad (3)
iphone (1)
meetup (8)
google apps (2)
lean startup (1)
open source (1)
jobs (1)
rails (5)
scrum (1)
nyc (4)
gtd (1)
beer (3)
selenium (1)
  • About
  • Case Studies
  • Team
  • Community
  • Careers
  • Contact
  • Labs
  • Events

Contact Us

contact@pivotallabs.com
+1 415-77-PIVOT
TwitterLinkedInFacebook

Pivotal Tracker

Tracker is the award-winning agile project management tool that enables real-time collaboration around a shared, prioritized backlog.
Visit pivotaltracker.com >