Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
View Active Browser Sessions (github.com/blog)
32 points by ruswick on Oct 14, 2013 | hide | past | favorite | 3 comments


If any GitHubbers are listening, please require credentials to revoke a session. Imagine the scenario in which a bad actor gets one of my session cookies - he can then hit this page, invalidate all of my sessions, and then aggressively use this page to keep me logged out of any new sessions, effectively locking me out of my account and preventing me from kicking him out.

Requiring authentication to revoke a session would fix that handily (or just make new sessions immune to revocation for 5 minutes or something)

That said, :thumbsup: on this. I really like having this kind of information available.


It should require "sudo" privileges now.


Awesome. Thank you!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: