Hacker News new | ask | show | jobs
by throwaway09223 1387 days ago
Well, that's a bug in the HTTP cookie spec. Regrettable, but as you note something that should have been foreseen. There's absolutely no excuse, as RFC6265 itself notes "cookies contain a number of security and privacy infelicities."

This bug is unrelated to port privileges