Excellent++. Stacking it such that signing in doesn’t drop it would also be a good idea. Or IP + User Agent string + time limit HMAC or something would’t need a cookie/session at all and make it such that a “replay” attack wouldn’t work in … 10 minutes (based on post time) or so. More secure than the login under HTTP. :P
In reply to Re^3: How about a "reclaim your post" feature?
by Your Mother
in thread How about a "reclaim your post" feature?
by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |