@mjg59@nondeterministic.computer
Post #3539526
2026-07-02 18:07 UTC
I spent a long time looking at what I think is about every standard for reducing risk around bearer tokens theft and why we still don't have nice things: https://www.codon.org.uk/~mjg59/blog/p/preventing-token-theft/
Replies (2)
-
@xabean@infosec.exchange 2026-07-02 20:32
@mjg59@nondeterministic.computer what happened to dreamwidth or whatever the livejournal thing you blogged on
-
@mjg59@nondeterministic.computer 2026-07-02 20:20
A few people have suggested binding tokens to IP addresses and while that definitely works the user experience of having to log back into everything because you've just moved to a different network is extremely bad