Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
mrmagooey
on June 14, 2017
|
parent
|
context
|
favorite
| on:
Securing your API: a modern alternative to CSRF to...
Isn't JWT a modern alternative to CSRF tokens?
vmasto
on June 14, 2017
[–]
It's not. If you think it is you probably store JWT unsafely instead of in an httpOnly secure cookie.
hawkweed
on June 15, 2017
|
parent
[–]
Why do you think storing JWT in secure cookie is only secure solution?
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: