Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How does that stop script kids from messing with the GET arguments? You are still passing state in the URL, no?


i can make the encoding of the data arbitrarily secure at a cost of time/space. in the simplest case of base64, it is just security by obscurity which is why i only asserted that it keeps out juvenile delinquents. if you want it to be robust then you must use encryption of course.


Signatures.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: