4 ms·
It's strictly more complex without much additional benefit. To have zero-trust random blob tracking you'd still need public key infrastructure, and you'd have a
by dub 5y ago
It's strictly more complex without much additional benefit. To have zero-trust random blob tracking you'd still need public key infrastructure, and you'd have a system which is overall more complex and has more ways to break (running out of data storage, network partitions to the database, etc.).
A revocation list would be a smaller, easier-to-distribute dataset if you were going to keep data related to specific tokens around.
- zabzonk 5y agoI don't see why you need a revocation list - you just need to check access date with the security key. And do a sweep say every couple of hours to delete the security keys that haven't been used.
- danbulant 5y agoIf a user decides to logout from certain device, or when you need to log out an active session early
- Sirened 5y agoRevocation is important for SSO and, generally, on corporate systems. When you fire an employee and suspend their systems access, you really don't want a dangling session token to be useable, so you need to support early revocation. The revocation lists will be comparatively very small and so distributing them is less of a challenge. It's mostly just a pain.