4 ms·
These are the ways the strategies differ: - a token can be invalidated individually, while resetting a password invalidates all sessions - a token can be give
by pushrax 7y ago
These are the ways the strategies differ:
- a token can be invalidated individually, while resetting a password invalidates all sessions
- a token can be given a predetermined expiry without the issues that arise from predetermined password expiry
- a token can be given a limited permission set
- a token can be used to track the origin and extent of an attack
In practise for something like TeamViewer I find it likely that none of these except the first would be implemented. If the attacker has access to the registry chances are you're f*cked anyway.
- Daniel_sk 7y agoAlso - a token can’t be used to change your password or steal the account completely. The app can ask you to enter your password again if you are doing these changes to your account. A token would not allow the attacker to pass this.