| 2) We really try hard to never break features during a security update, but sometime we have to correct some less secure behavior (or totally insecure one) and for those situations we are providing a way for legacy configuration to still work. It's highly recommended to not use the escape hatches for the long run but more for a short period of time, to have the time to adjust internal stuff etc. There is no plan yet to remove the previous escape hatches, but it's not meant to be used forever. We will perhaps use some telemetry to understand which ones are really used or not and remove the unused ones. If you have a particular situation when the session ID binding is important to not be used, please explain your scenario for us to better understand and perhaps to propose a different approach. |