Hacker News new | past | comments | ask | show | jobs | submit login

He’s right, though. I understand the risk of this session never expiring is the same as No sane person should ever request a token which never expires. Your fat tail of risk dominates the whole distribution of outcomes.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: