Hacker News new | past | comments | ask | show | jobs | submit login

I believe that it's that site's responsibility to set the cookie's secure attribute. Otherwise I'm surprised nobody mentioned disabling 3rd party cookies as a mitigation on the client side. Using a VPN provider, a VPS or even your self-hosted VPN in your home (your home ISP) is just choosing who you trust.



Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: