|
|
|
|
|
by moomoo11
755 days ago
|
|
But the token is used over SSL and the only way to get it afaik is to hijack the client device or somehow hijack the server. The first scenario is pretty rare and the second is pretty easy to avoid. I don’t think that’s really an edge case that’s concerning for 99% of applications. |
|
Yet we have millions of passwords in dumps across the internet. Maybe hijacking the client or server is more common than thought?