Hacker News new | ask | show | jobs
by firloop 2143 days ago
Oof. Depending on how they store authentication data, it might be possible to get someone's session token. Let's hope the cookies are "HttpOnly".