Quantcast
Channel: User R.. GitHub STOP HELPING ICE - Information Security Stack Exchange
Viewing all articles
Browse latest Browse all 50

Comment by R.. GitHub STOP HELPING ICE on What's wrong with my app authentication scheme?

$
0
0
Tokens should have unlimited lifetime, but should not be sufficient for performing sensitive/destructive actions like deleting account or changing credentials. Forcing a user to enter their password again just because a token "expired" is phishy behavior and makes your users less safe, not more. (Because once they've come to expect this to happen, they'll gladly also enter their password to phishing sites.)

Viewing all articles
Browse latest Browse all 50

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>