3 ms·
Not only one time tokens, but with limited life-span. So after a while the token expires and is useless. This is a must for such a scheme.
by PythonicAlpha 12y ago
Not only one time tokens, but with limited life-span. So after a while the token expires and is useless. This is a must for such a scheme.
- sturadnidge 12y agoBoth of these, plus a differentiator between 'current' and 'new' token requests - without that, it's an easy way to log people out of sites by simply knowing their email address. To the point about not always having access to email, it's a pretty simple denial of service vector.
- PythonicAlpha 12y agoCan you clarify, what you mean by "differentiator between current and new token requests"? Currently I don't exactly know which attack form you mean and how it could be prevented by such a "differentiator". (an example would be nice)