Slide 17
Slide 17 text
Session
Tokens
Caveats
Session cookie means page is not-cacheable
(Not even login pages)
Tokens are a target for attacks
Regeneration mandatory at key steps (logins, expiry)
Vulnerable to BREACH attacks
Token rotation means usability concerns
(e.g. broken form sumissions or "Back" buttons)