Skip to content

Comment on GitHub moves to SSL, but remains Firesheepable

Comments

We fat fingered the config. The cookie is marked secure now but we found another issue where it's being sent back on redirected HTTP requests. It should be all plugged up in a bit.

Okay. The session cookie is marked secure and is sent only in response to HTTPS requests. That should cover everything.

Somebody get this guy some karma.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.