Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
naasking
on Feb 21, 2017
|
parent
|
context
|
favorite
| on:
Cross-Site Request Forgery is dead
I don't know, at some point not supporting this feature would be equivalent to a running a browser with a flawed TLS implementation. The burden is on the user to keep their software up to date.
edgartaor
on Feb 21, 2017
[–]
Yep. >at some point In the meantime, I think it's better mitigate this kind of danger at the server side.
Consider applying for YC's Spring batch! Applications are open till Feb 11.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: