Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

An easier way to detect something fishy would be to allow at most one connection per auth token, and invalidate it and re-request login credentials if a collision occurs. Just ping both connections first to make sure they're both actually alive, and not the same machine logging in again after a reboot-after-crash.


Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: