Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

maybe, a better solution might be just doing a serverside 'authenticity ping' every x seconds, and if that fails then you get kicked out.

This would leave a window of x seconds after logging out in which attacks could occur but that could be mitigated by requiring a failed request on logout (perhaps require the usb key to be removed upon logout, send an auth-ping, and only give a successful logout message if the auth-ping fails. (Even without this mitigation I'm not sure what kind of attack would work for the inbetween X seconds, but might as well mitigate it in case someone else could think of something)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: