Hacker News new | ask | show | jobs
by dcaunt 4506 days ago
You're right, it's not an absolute fix.

It would have prevented requests from an authenticated browser (without a mobile UA) from being accepted, reducing the effectiveness of the attack.