Cloud Security · 2026-10-03 · 8 min

Whosoever Holds This Hammer: Bearer Tokens, Stolen Sessions and Proof of Possession

Mjölnir can only be lifted by the worthy. Most access tokens can be lifted by anyone holding them: steal the session cookie and you inherit the login, MFA and all. Proof-of-possession binds the token to a key the thief doesn’t have.

Read the full post on matx104.com.pk →