Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The current spec has a serious flaw for CSRF prevention - it doesn't include the protocol in the definition of site, only the domain. This allows a MITM'd http page to CSRF a https site. This same flaw is in cookies themselves - a cookie set over https is used for http requests.


I could be misunderstanding, but is that not what the secure cookie flag is for?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: