Skip to content

Comment on I Hacked News.YCparent

Comments

Browser bugs that steal content off other pages -- is that why oftentimes the session id is not used as the secret in side-effecting requests? I've seen a lot of sites use random unique secrets and wondered why they didn't just use the session id.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.