|
|
|
|
|
by mac-chaffee
1251 days ago
|
|
Is tying session tokens to IPs actually common? I can't imagine it is given the unreliability of IP addresses causing issues. I used to live somewhere where outbound traffic went through one of three CGNAT IPs at random, and I only had auth issues with one really old site that predates the NAT hell that is the modern internet. |
|
It would be possible to do some kind of check for "this session token was used in the US and Russia twenty minutes apart... something's fishy," but that adds in more complexity.