Hacker News new | ask | show | jobs
by walkon 4125 days ago
Good to see they fixed this security bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1095859

A proxy could inject cookies on a 407 response and even bypass the authentication prompt - could have been used for session fixation attacks.