Urgent.News

What's breaking now, across thousands of outlets.

Tech

Logging Out All Devices Did Not Log Them Out: Session Revocation Done Properly

-- title: "Logging Out All Devices Did Not Log Them Out: Session Revocation Done Properly" description: "Logging out of all devices clears one kind of credential. Browser sessions, OAuth grants to third party apps and legacy API tokens are three separate things, and access survives as long as any one of them is live. How to tell them apart, the order to revoke in, and what to re-check…

Logging out of all devices does not erase all credentials associated with an account. In fact, three separate systems must be addressed individually to ensure a comprehensive security reset: browser sessions, OAuth grants to third-party applications, and API tokens or application keys.

Browser sessions are the most immediate to revoke. Each device that holds a login generates a session credential with its own expiry date. The log-out-all-devices button effectively clears these sessions, forcing affected devices to sign in again. However, OAuth grants, which are long-lived tokens given to third-party applications when you log in, remain active even after a device-wide logout.

Similarly, API tokens and application keys, often generated when using developer tools or running scripts, are also unaffected by a general logout.

To properly revoke all credentials in the correct order, begin by removing access from any unrecognized or unused third-party applications in your account settings. Next, navigate to the application management area of the developer portal to invalidate any legacy API tokens and developer applications. Proceed to clear browser sessions on every device, then reset the account password. Finally, review and update the account's two-factor authentication method, ensuring that recovery options have not been tampered with.

While revoking credentials is crucial, it does not address what a malicious actor may have done while they had access. After revoking, it is essential to conduct a comprehensive review of the account. Examine the login history for unfamiliar devices or locations, check for any unauthorized changes to the account's recovery information, and scan for posts, bio updates, or follow/unfollow activity that wasn't initiated by you.

Additionally, regenerate fresh recovery codes for the two-factor authentication method to ensure the old ones are no longer effective.

Revoke credentials become necessary under certain circumstances, such as receiving a suspicious sign-in alert from an unfamiliar device, losing or replacing devices that held login credentials, undergoing significant changes in third-party tool usage, or experiencing a data breach where an associated email address was compromised.

It is important to change the password first, but not until you have thoroughly revoked all other credentials, as changing the password alone does not invalidate OAuth grants or API tokens. In cases where there is evidence of unauthorized access, prioritize recovering control of the account before conducting cleanup actions.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Monday 28 September →