Hacker News new | ask | show | jobs
by ElectricalUnion 1522 days ago
> an XSS on Lenovo's site make it possible to leak these?

Not if they're HttpOnly cookies. Then it requires actually compromise/mitm of the application server code to recover the cookies.