Technoguyfication,
Technoguyfication avatar

Not really. A session token has a lot more entropy and is far harder to crack than a user's password. Session tokens shouldn't last forever but that's why rolling tokens are a thing. You should use a valid token to periodically refresh the token for a new one, and expire the previous one.

It's less secure to repeatedly sign users out and force them to request new session tokens by re-transmitting their password to the server. You want to reduce the amount of times you have passwords going over the wire (even if encrypted) and being stored in the server's memory.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • memes
  • GTA5RPClips
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • osvaldo12
  • ethstaker
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • ngwrru68w68
  • kavyap
  • tester
  • cisconetworking
  • megavids
  • InstantRegret
  • khanakhh
  • cubers
  • everett
  • Durango
  • tacticalgear
  • Leos
  • modclub
  • normalnudes
  • provamag3
  • anitta
  • JUstTest
  • lostlight
  • All magazines