Hacker News new | ask | show | jobs
by kerng 2485 days ago
Pass the cookie attacks are problematic (e.g in case someone already has root access, which is the concern here).

Hacker will just wait until after auth and steal your cookies.