Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That is not a thing a cookie can do, so while it may be sad, there's not much to be done about it.


That's a main point of the paper: taking legit sessions from Attacker and shoving them into Victim, then being able to spy on Victim even when Victim is on HTTPS. Apps aren't handling this case well, as in the example of being signed into GMail under Victim, but showing the chat widget of Attacker.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: