3 ms·
Do you have any thoughts on their mitigations? I would like to protect against attacks like this, but their mitigations seem to have big drawbacks: > Bind Sess
by MaxGabriel 7y ago
Do you have any thoughts on their mitigations? I would like to protect against attacks like this, but their mitigations seem to have big drawbacks:
> Bind Sessions to IP Addresses
As they admit, "IPs... change for legitimate reasons", so it seems like most sites wouldn't want to roll out this protection, because it would randomly logout their users. I haven't tested this, but it seems like this would be pretty common on mobile networks from some googling.
> Bind Sessions to Devices
They say they will "investigate binding the session to a specific device"; is there a known good way to do this? I could imagine attempts to do this breaking legitimate use cases like Apple's Handoff between iOS and Mac, or just not adding much security.
My instinct is that the admin functionality could be put run behind a VPN, and that would be a good defense against a HackerOne employee's credentials or sessions cookie being leaked.
- codexon 7y agoFor such a highly valuable website like hackerone, IP binding should be done, the extra security is worth the slight annoyance at having to relog when your IP changes.