Hacker News new | past | comments | ask | show | jobs | submit login
View Active Browser Sessions (github.com/blog)
32 points by ruswick on Oct 14, 2013 | hide | past | favorite | 3 comments



If any GitHubbers are listening, please require credentials to revoke a session. Imagine the scenario in which a bad actor gets one of my session cookies - he can then hit this page, invalidate all of my sessions, and then aggressively use this page to keep me logged out of any new sessions, effectively locking me out of my account and preventing me from kicking him out.

Requiring authentication to revoke a session would fix that handily (or just make new sessions immune to revocation for 5 minutes or something)

That said, :thumbsup: on this. I really like having this kind of information available.


It should require "sudo" privileges now.


Awesome. Thank you!




Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: