Hacker News new | ask | show | jobs
by gcb0 4428 days ago
Always assumed the response was via post... It's silly to use get/url for that. Any ad or external library on the page can already see that then.. Everyone logs referer headers. Even using custom fonts directly from Google is already advertising your tokens...