Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I do agree with this. It's too much mollycoddling from browsers and in fact dis-incentivizes manufacturers to fix the real CSRF vulnerabilities...

Heaven forbid if someone joins your LAN with a device running an old/weird browser that doesn't do this preflighting and your intranet just gets caught with its pants down...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: