(no title)
nathansherburn | 8 months ago
E.g. If you set your session timeouts to a ~1 day then by the time your session cookies are up for sale on the dark web, they will be expired.
The article doesn't mention this and it's the main reason I advocate for auth sessions that are as short as practical.
throw14082020|8 months ago
TacticalCoder|8 months ago
[deleted]