Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

unlikely to affect you if you're already embedding CSRF tokens in your responses, which would defeat caching anyway. Curious if this response length fiddling will mitigate the attack, can anyone more knowledgeable than me confirm?


interesting point that CSRF tokens break caching. People can store it in cookie, and not put into the actual HTML.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: