|
|
|
|
|
by mtlynch
1259 days ago
|
|
Yeah, good point. I guess it'd be a pain to have to keep reauth'ing if your IP changed for legitimate reasons. It would be possible to do some kind of check for "this session token was used in the US and Russia twenty minutes apart... something's fishy," but that adds in more complexity. |
|