Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's interesting to see software engineers going from rolling their own auth, to not rolling their own auth, to not even noticing this quite blatant security problem.

It doesn't matter if you roll your own auth or not, you need to understand a very basic fundamental of it all: never trust the client.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: