Live data from Hacker News

Session Tokens Explained

blog.meshstudio.io

1–2 of 2 posts

Re: Session Tokens Explained

#2
"Key Obscurity

When we’re storing these tokens in a browser, or header, there’s no point in calling out what it’s there for. Don’t use keys that are obvious, such as “SESSION_TOKEN”, opt for something that doesn’t imply to an attacker that this is where they should be concentrating their efforts."

Closes tab, shakes head...