Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
jcampbell1
on July 16, 2019
|
parent
|
context
|
favorite
| on:
Cracking My Windshield and Earning $10k on the Tes...
The trend of storing auth tokens in localStorage rather than httpOnly cookies is a problematic trend due to vulnerabilities like this. If you can exfiltrate an authtoken then one gets long lived access to the system.
Consider applying for YC's Spring batch! Applications are open till Feb 11.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: