Hacker News new | ask | show | jobs
by ergo98 5711 days ago
It's kind of shocking that the session vulnerability seems to be so new to so many. It is painfully obvious. It's one of the reasons that many sites demand that you enter your old password before entering a new password (ensuring that, in the event someone steals your session cookie [which includes simply accessing a public PC], at least it's a temporary vulnerability).

This particular entry, however, uses the worn and now ridiculous "fail" meme five different times. Fail.