5 ms·
This got flagged by our pentest vendor as well, but to me it sounds like a very unrealistic attack vector. If one can steal a token from your browser's storage
by hkai 5y ago
This got flagged by our pentest vendor as well, but to me it sounds like a very unrealistic attack vector.
If one can steal a token from your browser's storage or can intercept your HTTPS connection, then sure, yes, you have a huge vulnerability even without JWT.
- quickthrower2 5y agoCould make you less secure if the token was leaked somehow (another vuln for example a cross origin type of thing) You notice odd behaviour so you log out to stop it but the attacker isn’t logged out. Also with this setup log out of all devices is not possible! Again something you’d be keen to do if seemingly attacked.
- porker 5y agoI've never got my head round how log out of all devices works. It has to have a central store of all sessions?
- lbriner 5y agoIt depends on what auth you are using. In OpenID Connect, there are back channels that talk to each other so that all devices know you have logged out. If you are using traditional auth then yes, you would need to track session state against the user so that when they access from a particular device, you could check whether they have already logged out. Some more complex apps use a background thread to check auth status with the server.
- porker 5y agoThanks for the insight. As Google has this feature I've wondered how they get it to scale up.
- wglb 5y ago> it sounds like a very unrealistic attack vector. It isn't unrealistic at all. A lot of attack vectors seem unrealistic to the victim until they happen. How realistic is it to think that a hostile actor can inject their code into a build process without touching the disk, then get that corrupted executable signed; then that signed executable is installed by 18000 users with root permission?