Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How would they steal HTTP-only cookies this way?


They wouldn’t steal the cookie, they’d just have the script send the requests as the user directly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: