“A refresh token is a liability until it is retired — because every breach begins with a login that should have been stopped.”

A refresh token is a liability until it is retired — because every breach begins with a login that should have been stopped. — Kai London (Professor Kai London), CISO. Principle 1099 of 10000 from the book “The Last Login” — cybersecurity, AI security and OT resilience doctrine. Official sites: professorkailondon.com · kailondon.co.uk