Security experts warn that infinite-lived refresh tokens pose a major security risk
A refresh token without an expiry date functions similarly to a permanent password, negating the security benefit of short-lived access tokens. These tokens, defined in technical standards RFC 6749 and 6819, allow attackers prolonged access if stolen, as they can be replayed without user interaction. Common problematic configurations include issuing tokens without expiration, not binding them to a specific device, and failing to rotate them upon use. This setup bypasses security measures like password changes and multi-factor authentication, making stolen credentials highly valuable to attackers.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in