4 ms·
So... basically... the same thing you could already do with sqlite? ETA: And really, more websites need to bind cookies to an IP address (or at least a /24). A
by zonidjan 8y ago
So... basically... the same thing you could already do with sqlite?
ETA: And really, more websites need to bind cookies to an IP address (or at least a /24). Although if the attacker's got code execution that won't really help. (Nothing will.)
- Ayesh 8y agoI don't think _many_ web sites do this. I travel quite a lot, and sometimes connect without a VPN. Last time I login to Google was from Sri Lanka, and now I'm in Georgia, having g traveled everywhere in Europe and South East Asia (so not the same /24), but I never had to log in again. The same goes for Facebook, GitHub, HN, Reddit, Yahoo, and Hotmail. These are enough to ruin someones life I guess. I love how Github's access system works. Everytime I want to delete something, add SSH/GPG keys, etc, they prompt the passwords again.