3 ms·
Actually if browser used plain old smartcard cert off yubikey for client cert auth it would be prevented, but that's too PITA to use. Well, if implemented righ
by ilyt 3y ago
Actually if browser used plain old smartcard cert off yubikey for client cert auth it would be prevented, but that's too PITA to use.
Well, if implemented right. Techically every ssl connection would carry user's identity so cookie with that identity wouldn't even be required
- insanitybit 3y agohttps://learn.microsoft.com/en-us/windows-server/security/token-binding/introducing-token-binding https://learn.microsoft.com/en-us/windows-server/security/to... Sounds like token binding.