Hacker News new | ask | show | jobs
by apitman 965 days ago
I'm referring to threat models where the attacker might be able to manipulate time on the server, either directly or through NTP servers, etc. Personally it's not something I would worry about but I've heard it discussed and was wondering how big a concern it is.
1 comments

Well, then you still end up more secure than a regular session token.