Hacker News new | past | comments | ask | show | jobs | submit login

Sounds like a great tool. But saying "CRSF is dead" is a sure sign you aren't taking security problems seriously enough. The post itself describes how the feature has built-in self-weakening features. So CRSF is dead... so long as you use this feature on any appropriate cookies, and work around it only sparingly meanwhile keeping in mind these very common use cases where it badly breaks expected behavior in a way that will encourage workarounds that reinstate CRSF risk. But totally dead.



Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: