Hacker News new | ask | show | jobs
by Scoundreller 4351 days ago
This may not be the ideal place to ask this but here it goes:

What about authenticating a logout? If someone is intercepting your communication, and you logout, how can you be sure that your logout has actually executed?

The "You have signed out" page could display a one-time code that should match a second set of seemingly randomly generated codes on your mobile phone.