• Daniel@lemmy.mlOP
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      3
      ·
      11 months ago

      Fair point, I made the meme to be silly, and, yes, this is one of the many reasons why tokens in general should expire after some point in time.

      Also the meme isn’t wrong, memes don’t need logic, they’re supposed to give people a giggle.

        • Daniel@lemmy.mlOP
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          2
          ·
          11 months ago

          To be Frank, who I am not (I’m Hai), I can’t tell if you’re a troll or not. Although, if you’re not, my meme is not “wrong” or spreading misinformation it contains a logical fallacy, as many jokes do. I can list jokes that contain logical fallacies upon request.

          • 7heo@lemmy.ml
            link
            fedilink
            arrow-up
            5
            arrow-down
            1
            ·
            edit-2
            11 months ago

            Bruh, pointing out that “you’re spreading out misinformation as a joke” isn’t trolling. I’d recommend going out to touch grass, but given how thin your skin is, I am afraid you’re at aggravated risks of third degree burns from the slightest sun exposure, even during a cloudy day. So I’ll recommend for you to wear a thick coat and go see a dermatologist instead.

            P.S.: nice pun, I loled.

    • NightAuthor@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      11 months ago

      Look at this guy over here, nerding out about the WiFi.

      Jk, glad to find someone in the comments correcting the misinformation in the meme. OP is probably a hacker who likes to do session hijacking.

    • redcalcium@lemmy.institute
      link
      fedilink
      arrow-up
      4
      ·
      11 months ago

      JWT sounds great on paper until you have to deal with logout and revocations. Might as well use standard session cookies.

          • 7heo@lemmy.ml
            link
            fedilink
            arrow-up
            2
            ·
            edit-2
            11 months ago

            Yeah, so lemme show you a few tools since we’re on the topic of sharing.

            1. Find the tool that tickles your fancy here or here.
            2. Find a target (for this part I won’t be giving any links).
            3. Once you have access to your target, run your file recovery tool (winfr, testdisk, etc).
            4. Bring back any and all cookies.
            5. Exfiltrate them using twitter, github, email, whatever.
            6. Congratulations, you now have access to all the (not yet expired) sessions (i.e. accounts) your target ever used, because they follow(ed) the recommendations in the meme of OP and in your comment.

            Please log out from apps and websites!

          • 7heo@lemmy.ml
            link
            fedilink
            arrow-up
            1
            ·
            edit-2
            11 months ago

            Depends on your (actually, their, for example if it implies ephemeral server sessions) definition of “incognito”. But if you mean “incognito” as in “private browsing”, it makes no difference (as it has no server side impact whatsoever).

            A file is a file, a remote database entry is a remote database entry. You need both gone (and securely deleted, as in srm(1), to be really and irredeemably logged off).

            Admittedly, secure deletion doesn’t really matter on the server side, as restoring deleted files require filesystem level access on the server, and if an attacker has that, you’ve got other things to worry about.

            • SnipingNinja@slrpnk.net
              link
              fedilink
              arrow-up
              2
              ·
              11 months ago

              Yeah, that’s what I was curious about, the security issues you mentioned as I wasn’t clear in my understanding until now. Thanks.

    • 4am@lemm.ee
      link
      fedilink
      English
      arrow-up
      1
      ·
      11 months ago

      Yeah you really should do both. Some session cookies can just be used as tracking cookies later.