5 ms·
Is tying session tokens to IPs actually common? I can't imagine it is given the unreliability of IP addresses causing issues. I used to live somewhere where ou
by mac-chaffee 4y ago
Is tying session tokens to IPs actually common? I can't imagine it is given the unreliability of IP addresses causing issues.
I used to live somewhere where outbound traffic went through one of three CGNAT IPs at random, and I only had auth issues with one really old site that predates the NAT hell that is the modern internet.
- numbsafari 4y agosession vs refresh… you kill the session token and require a refresh. Can be sometimes be transparent, but may cause a re-authentication using the second factor with an indicator to the user that their previous session was killed due to use by a different IP. If you are concerned about stable IPs, use a proper VPN or bastion setup.
- mtlynch 4y agoYeah, good point. I guess it'd be a pain to have to keep reauth'ing if your IP changed for legitimate reasons. It would be possible to do some kind of check for "this session token was used in the US and Russia twenty minutes apart... something's fishy," but that adds in more complexity.