Recently, Rails added AEAD encrypted cookies: rails/rails#28132 We currently encrypt using SHA1: https://github.com/sinatra/sinatra/blob/1b0edc0aeaaf4839cadfcec1b21da86e6af1d4c0/rack-protection/lib/rack/protection/base.rb#L111 /cc @jkowens @mikeycgto