Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
driverdan
on Feb 14, 2013
|
parent
|
context
|
favorite
| on:
Unofficial documentation of the Tesla Model S REST...
Hello XSRF! Cookie only authentication? Seriously?
timdorr
on Feb 14, 2013
[–]
This is only accessed directly via library, so CSRF isn't a factor. Also, everything is happening over SSL.
mikeash
on Feb 14, 2013
|
parent
[–]
SSL wouldn't save you, but if you never get the magic cookie into a browser then you're safe from XSRF.
Consider applying for YC's Summer 2025 batch! Applications are open till May 13
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: