Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
yencabulator
6y ago
0 comments
Share
The http version can't access secure cookies; https with the wrong cert can use the secure cookies of the real https site.
0 comments
default
newest
oldest
mrob
6y ago
So disable secure cookies by default for self-signed certs. The scary warnings can be shown when the user tries to enable them.
ivanbakel
6y ago
In other words, "open users up to social engineering attacks to make my web-dev life easier".
lucideer
6y ago
You misinterpreted the above commenter. The suggestion is to disallow self-signed contexts access cookies set in authoritative contexts.
1 more reply
j
/
k
navigate · click thread line to collapse