Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not for all clients, everywhere. It could be an old version of the Android app, given his mention of Cyanogen.


If you know of any such endpoints you should report them. Sending auth cookies over HTTP is a security vulnerability.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: