Y
Hacker News
new
|
ask
|
show
|
jobs
Protect your reset password tokens: UK Data Protection position on referers
(
iconewsblog.wordpress.com
)
1 points
by
fastmark
3922 days ago
1 comments
fastmark
3922 days ago
If you wish to use Reset Password tokens, then be sure to block referers and/or not include any third party loaded assets (JavaScript, css, etc).
It's not just reset password tokens: beware any protected data, like PII (emails, etc)!
link
It's not just reset password tokens: beware any protected data, like PII (emails, etc)!