8 ms·
The post doesn't say you should give out your login. It says you should encrypt your access tokens and explains some security implications of current implementa
by akane 8y ago
The post doesn't say you should give out your login. It says you should encrypt your access tokens and explains some security implications of current implementations that use them, like how they often give too broad permissions. When you change your password, you often need to reauth all of your devices, but you don't need to reauth your access tokens.
- Arzh 8y agoWhy would I want the access tokens to be revoked if I change my password, unless I revoke the token it should be valid.