Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
phpnode
on Aug 6, 2013
|
parent
|
context
|
favorite
| on:
Security advisory: Breach and Django
unlikely to affect you if you're already embedding CSRF tokens in your responses, which would defeat caching anyway. Curious if this response length fiddling will mitigate the attack, can anyone more knowledgeable than me confirm?
homakov
on Aug 6, 2013
|
prev
[–]
interesting point that CSRF tokens break caching. People can store it in cookie, and not put into the actual HTML.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: