Hacker News new | ask | show | jobs
by londons_explore 1379 days ago
Not using HTTPS opens up a bunch of new possibilities of how to cheat...

Can you send an http request spoofing the IP address it's from? I bet you could with enough attempts because you only have to successfully guess the TCP syn cookie once...