Server side sessions are still valid until you signal to the server to invalidate (destroy) them.
That’s why “signing off” isn’t remotely the same as deleting cookies, and that’s why jwt are fundamentally a bad idea, especially without expiration.
This meme is wrong. It’s the logical equivalent to saying that “extinguishing a fire” and “closing your eyes” are the same thing (as it makes the fire disappear to you), but that closing your eyes is just more convenient.
To be Frank, who I am not (I’m Hai), I can’t tell if you’re a troll or not. Although, if you’re not, my meme is not “wrong” or spreading misinformation it contains a logical fallacy, as many jokes do. I can list jokes that contain logical fallacies upon request.
@7heo@tdawg, i only keep data from sites which i visit every day, no other, using Site Bleacher, it remove automatically cookies, local storages, IndexedDBs, service workers, cache storages, filesystems and webSQLs from all not whitelisted sites. This keeps clean the browser and HD.
Server side sessions are still valid until you signal to the server to invalidate (destroy) them.
That’s why “signing off” isn’t remotely the same as deleting cookies, and that’s why jwt are fundamentally a bad idea, especially without expiration.
This meme is wrong. It’s the logical equivalent to saying that “extinguishing a fire” and “closing your eyes” are the same thing (as it makes the fire disappear to you), but that closing your eyes is just more convenient.
Fair point, I made the meme to be silly, and, yes, this is one of the many reasons why tokens in general should expire after some point in time.
Also the meme isn’t wrong, memes don’t need logic, they’re supposed to give people a giggle.
expired
To be Frank, who I am not (I’m Hai), I can’t tell if you’re a troll or not. Although, if you’re not, my meme is not “wrong” or spreading misinformation it contains a logical fallacy, as many jokes do. I can list jokes that contain logical fallacies upon request.
expired
This was the funniest thing I read all day, thank you. Sorry for misunderstanding your tone.
Look at this guy over here, nerding out about the WiFi.
Jk, glad to find someone in the comments correcting the misinformation in the meme. OP is probably a hacker who likes to do session hijacking.
Not a hacker, just a silly goofball.
JWT sounds great on paper until you have to deal with logout and revocations. Might as well use standard session cookies.
expired
Fr my thoughts exactly
And what happens next time they load the site?
expired
@7heo @tdawg, i only keep data from sites which i visit every day, no other, using Site Bleacher, it remove automatically cookies, local storages, IndexedDBs, service workers, cache storages, filesystems and webSQLs from all not whitelisted sites. This keeps clean the browser and HD.
https://github.com/wooque/site-bleacher
Similar alternative
https://github.com/Cookie-AutoDelete/Cookie-AutoDelete
expired
What about incognito sessions?
expired
Yeah, that’s what I was curious about, the security issues you mentioned as I wasn’t clear in my understanding until now. Thanks.
Yeah you really should do both. Some session cookies can just be used as tracking cookies later.
expired