Hacker News new | ask | show | jobs
by QAkICoU7IDNkpFu 307 days ago
“The user will have to be logged in on Facebook for this to work, but we know many people keep Facebook open for easy access.”

Well there's your problem right there.

1 comments

Bog-standard CSRF is what that is. It’s essentially the second thing you guard against, right after sanitizing inputs to prevent XSS and SQL injection.