Hacker News new | ask | show | jobs
by badkins 5472 days ago
The solutions mentioning IP addresses won't solve the problem. For someone to use firesheep to steal session keys, they have to be on the same network, such as a coffee shop's wifi. Your website will see any request from that network as the same IP address.

this solution will not stop the attacker until he leaves the coffee shop.