Yes. The default rails for session management are susceptible to theft.
This is because it conveys to the client all the information that the client requires of himself in order to identify himself in HTTP cookies. For the most part, anyone who can intercept an HTTP connection can take on client authentication from a Rails perspective.
The simplest countermeasure is to only serve your site via HTTPS, and Rails is secure cookies that tell the browser to only send this cookie via HTTPS. The safety guide contains more helpful tips.
source share