Skip to content

Commit

Permalink
#1610 - no reference, no problem (remove outdated section text)
Browse files Browse the repository at this point in the history
  • Loading branch information
Elar Lang authored and tghosth committed Oct 28, 2024
1 parent bf9642d commit 68f314a
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion 5.0/en/0x12-V3-Session-management.md
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,7 @@ This section relates to those writing Relying Party (RP) or Credential Service P

## V3.7 Defenses Against Session Management Exploits

There are a small number of session management attacks, some related to the user experience (UX) of sessions. Previously, based on ISO 27002 requirements, the ASVS has required blocking multiple simultaneous sessions. Blocking simultaneous sessions is no longer appropriate, not only as modern users have many devices or the app is an API without a browser session, but in most of these implementations, the last authenticator wins, which is often the attacker. This section provides leading guidance on deterring, delaying and detecting session management attacks using code.
There are a small number of session management attacks, some related to the user experience (UX) of sessions. This section provides leading guidance on deterring, delaying and detecting session management attacks using code.

### Description of the half-open Attack

Expand Down

0 comments on commit 68f314a

Please sign in to comment.