Hacker News new | ask | show | jobs
by rnhmjoj 3807 days ago
What if someone is listening to your traffic and injects a script which sends generated passwords to a server? http only is a bad idea in this case.