Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So you keep client cookies and auth tokens… somewhere?


Sounds like one of those cases where convenience trumps security for business users and the engineers keep their palms close to their faces.


There is a payment provider in Europe that has become rather popular, who implement "instant" payments by asking for your online banking credentials... Security best practices always go out the window when they interfere with the business case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: