3 ms·
It’s not about the “logout button”. It’s basic security to handle the “stolen device” use case.
by layoutIfNeeded 5y ago
It’s not about the “logout button”. It’s basic security to handle the “stolen device” use case.
- quonn 5y agoIs that a practical use case? For a token that‘s valid for one hour? And the device is presumably locked. Is it really realistic that a user realizes quickly that the device is stolen and worried that it will be unlocked quickly and then actually logs in on another device to revoke the session of some website they were using (I wouldn‘t even know this is possible, how would a user know!) and that just to invalidate the token that would expire anyway within 30 minutes on average? Is that even remotely realistic to say nothing about „basic“? I had (fully encrypted) devices stolen, of course, and I did revoke keys and changed passwords (just in case). But I never managed to do this within one hour and there was never a risk of anyone unlocking the device anyway.