Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

We assume no if statements that implement a security check are safe without something. It’s not just bounds checks and type checks.

Origin checks are a special case worth considering. I am not sure what you describe would be exploitable in practice (reasons too long to fit in this margin) but worth looking into.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: