Hacker News new | ask | show | jobs
by jfgiogktkt 1864 days ago
You logout on a public computer, the next user undeletes the cookie (which is just a row in a profile SQLite database).
1 comments

Couldn't the previous user have rigged the app to not send the logout request, or way more plausibly installed a keylogger to get your password, which allows them to log in again at will?

I'm not disagreeing with you, it just seems to only cover a very specific type of attack, if someone else can mess with software. And of course if they can't it is unnecessary.