4 ms·
Refresh token rotation seems to be the standard mitigation (https://auth0.com/docs/tokens/refresh-tokens/refresh-token-rotation https://auth0.com/docs/tokens/re
by windowsworkstoo 6y ago
Refresh token rotation seems to be the standard mitigation (https://auth0.com/docs/tokens/refresh-tokens/refresh-token-rotation https://auth0.com/docs/tokens/refresh-tokens/refresh-token-r...)
- tftyeti 6y agoSure, that mitigates the risk when an attacker finds a refresh token later and it's no longer valid because of rotation. And it means that a stolen refresh token would probably be noticeable because the legitimate user wouldn't be able to use it anymore. But in many attack scenarios the attacker would get the refresh token immediately and the time until discovery would be enough for them to cause damage, right?
- dwaite 6y agoGenerally there is a big overlap between attack scenarios that allow for token exfiltration and attack scenarios that allow for code injection. Someone doesn't need to exfiltrate a token to make the client do their malicious requests right on the user's device. And certain external mitigations, like anomalous API usage detection, won't see odd time-of-travel restrictions based on the estimated geolocations of two different IP addresses or a change in the user agent behavior (different user-agent header, different networking stack behavior, etc). The difference is that some people argue that one of them is in scope for security measures, while the other is out of scope.