3 ms·
"They're short lived and meant to mitigate the damage done by having one or even several leaked." No. Reducing the time frame does not limit what can be done w
by rauar 14y ago
"They're short lived and meant to mitigate the damage done by having one or even several leaked."
No. Reducing the time frame does not limit what can be done with illegal access at all.
And there's nothing in the spec. afaik which says at all what short lived means exactly (in terms of seconds, minutes whatever). Probably short-lived needs to be long-living enough to perform some operation in the context of the applications author(s) - otherwise the token would be pointless. In the same time an attacker could use it without any issue as well (minus time of the take-over action).