The long string is based on applying a hash function to parameters of the VM session. The long strings can theoretically
be guessed. Practically however, various system administrator techniques for blocking distributed denial-of-service attacks
can be used to prevent scripted guessing, even when the attacker uses multiple machines. Moreover, even if an attacker
correctly guesses such a string, that secret is valid only for the lifetime of one VM session.
One important downside of sending around URLs that provide direct VM access is that, without additional security
measures, the access delegation messages could be intercepted by malicious Internet users. Fortunately, care institutions are likely to have secure messaging tools in place and therefore the access delegation message can be sent securely from the MyPHRMachines web server to the inbox of the caregiver.Therefore, we do not consider this as a major threat.