top | item 15804593

Session Tokens Explained

1 points| taylorhalliday | 8 years ago |blog.meshstudio.io | reply

1 comment

order
[+] bigiain|8 years ago|reply
"Key Obscurity

When we’re storing these tokens in a browser, or header, there’s no point in calling out what it’s there for. Don’t use keys that are obvious, such as “SESSION_TOKEN”, opt for something that doesn’t imply to an attacker that this is where they should be concentrating their efforts."

Closes tab, shakes head...