Hacker News new | ask | show | jobs
by goodpoint 1890 days ago
Even that is often not enough: sessions are long lived and very often stealing a cookie is all the attacker needs.