Hacker News new | ask | show | jobs
by raron 30 days ago
> Use short expirations

And now you can use time correlation attack to unmask people.

1 comments

How? The websites don't see anything consistent from one session to the next. They can't tell when the credential is renewed, and don't see a credential id.