5 ms·
One technique is to hold other information along with the session cookie, such as the client IP. This isn't perfect, because there will be false positives that
by jeffasinger 13y ago
One technique is to hold other information along with the session cookie, such as the client IP.
This isn't perfect, because there will be false positives that log people out fairly often, but it would make session hijacking significantly harder.
- simonw 13y agoI use a laptop and carry it between work and home, occasionally signing in to a VPN. My IP address changes several times a day.
- woadwarrior01 13y agoAdd a hash of the userAgent in the session. How about adding some shared secret in the browser's localStorage?