5 ms·
Security I implemented in the 90's: Encode the client IP address into the cookie. Also include a timestamp to force re-authentication at some point. This isn'
by excitom 5y ago
Security I implemented in the 90's: Encode the client IP address into the cookie.
Also include a timestamp to force re-authentication at some point.
This isn't rocket science.
- jshmrsn 5y agoWouldn't the cookie then be invalidated if you e.g. switched between WiFi and cellular on mobile?
- __turbobrew__ 5y agoYes, it would be invalidated. This would not work well on roaming devices.
- josho 5y agoAnd now as I connect between ipv4 to v6, connect to my VPN, switch from wifi to mobile data each change requires a login and I very quickly abandon your app for one that doesn’t force multiple authentications throughout the day.
- tgv 5y agoNot only that. I tried the same approach, but one of our clients has some kind of VPN and the user’s IP address would change regularly.
- VectorLock 5y agoGood luck with that on mobile.
- ohyeshedid 5y agoUntil CGNAT cripples your concept.
- j4yav 5y agoDevices are much more portable since the 90s and are likely to change networks frequently.