Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>> Fine, revoke the master token on the authentication server and after 5 minutes at the latest

That might be fine for a lot of use cases. But anything that can steal money using that token and 5 minutes is a very long time indeed.



    But anything that can steal money using that token and 5 minutes is a very long time indeed.
Then implement a check for the token in destructive operations. Should keep the performance impact pretty low.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: