Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
0 points
walkon
15y ago
0 comments
Share
Require SSL on any request who's response sends a set-cookie http header. Leave it out for the non-sensitive request/responses.
undefined | Better HN
0 comments
default
newest
oldest
santry
15y ago
You'd still be able to get the cookie when the client sends it bnack to the server on subsequent, non-SSL requests.
It's gotta be SSL all the time.
1 more reply
j
/
k
navigate · click thread line to collapse