3 ms·
> It would tremendously simplify for services. They now need not implement any cryptography. Uhh.. I sure hope the cookie tokens are not stored directly on the
by daave 13y ago
> It would tremendously simplify for services. They now need not implement any cryptography.
Uhh.. I sure hope the cookie tokens are not stored directly on the server-side, but rather verified against a (cryptographic) hash of same. These credentials are as valuable to an attacker as a password (albeit relatively short-lived).