Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Web Storage: the lesser evil for session tokens

Summary

James Kettle argues Web Storage (sessionStorage/localStorage) is often a safer home for session tokens than cookies, examining the Secure flag, HttpOnly and the path attribute.
Published
Collected

original ↗

Related coverage

back