Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Doing server side IP checks is already easy, but in reality it can lead to massive amounts of user complaints when their sessions keep disappearing, because as it turns out, some user segments have a lot of users coming through proxies where each request is not guaranteed to come from the same IP.


Or their mobile device roams from WiFi to cell data.

I suspect anyone suggesting that an IP be part of the session security has never actually tried it on a large scale.


Sure. It'd be nice to have some kind of actual standard to at least make a good best guess here. Cookies are a really, really bad start.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: