4 ms·
What? Why whould the signaure be invalidated?
by vasachi 4y ago
What? Why whould the signaure be invalidated?
- b3morales 4y agoNot the cryptographic signature; they mean the authorization. I.e. if the user's password has been compromised, then the attacker with the password could have started a new session using it. The question is, how do you (allow the user to) revoke the auth that was granted by the compromised password and invalidate that fraudulent session.