Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Here is the catch:

> So now what happens if a clever hacker is embedding this to his website and social engineers a victim to visiting his site. >

If that happens then CSRFs or JSON is not the highest priority thing to worry about. The hacker controls everything. And no matter what I do, he can find a by pass.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: