|
|
|
|
|
by z-factor
4695 days ago
|
|
The attacker has to be able to issue requests on behalf of the user with injected "canary" strings. I fail to see a practical exploit where one can do this and wouldn't have access to the secret in the response anyway. What am I missing? |
|