Skip to content

Comment on Cookie Bomb or Let's Break the Internet

Comments

There's a similar self-denial of service you can run into when you're injecting javascript and cookies into third-party pages.

Optimizely (YC W10) had this problem when they were setting cookies on a single domain across all of their customer sites. If you happened to be the kind of user that visited websites that had a high chance of using Optimizely, you quickly accumulated enough cookie to make their fronting proxy reject your request for their JS.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.