|
|
|
|
|
by davepeck
5194 days ago
|
|
I agree in principle. And I have built a custom CSRF page to help my potential customers out. In practice, lots of my potential users don't even understand that their AdBlock/whatever extensions are mucking about with Cookies in ways that break things. It's a tough sell to tell someone who is thinking about trying your service: "sorry, I don't work with your browser the way it is" when so much of the rest of the world is either HTTP, not HTTPS, or simply has decided to punt on CSRF or be much more selective about it. It looks to them like _I'm_ the one that's broken. Argh. It's no-win. |
|