3 ms·
Defense in depth. Nothing wrong with multiple solutions. You are absolutely correct that what they implemented as a great defense tactic. However, sometimes ask
by adam_baldwin 17y ago
Defense in depth. Nothing wrong with multiple solutions. You are absolutely correct that what they implemented as a great defense tactic. However, sometimes asking for credentials again to perform a privileged action is not acceptable for an application. I will admit that tokens are bad if XSS is possible as tokens can possibly be obtained by the attacker.