3 ms·
The tokens are cryptographically signed with a shared secret between the main server and analytics server. So an attacker can't forge another user's token. IP a
by pindi 14y ago
The tokens are cryptographically signed with a shared secret between the main server and analytics server. So an attacker can't forge another user's token. IP addresses would be a good solution also, especially if you need to track anonymous users.
- nivla 14y agoAhh I see, thats a good trick, the use of cryptographic signatures din't crossed my mind.