Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I suspect that's the actual best solution if avoiding session stealing is that big of a concern

that big of a concern for whom? Google doesn't care because Google has constructed a world where when something goes wrong, sorry, it's on you.

Your bank does care because if something goes wrong, it's frequently on them. The bank times you out to protect them more than you.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: