Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
JMTQp8lwXL
on March 13, 2020
|
parent
|
context
|
favorite
| on:
Slack account takeovers using HTTP Request Smuggli...
Given how widely publicized request smuggling was, I'm surprised it's still a problem for apps with large user bases like Slack.
lonelappde
on March 13, 2020
[–]
Other commenters note that some platforms intentionally leave this vuln open because closing it breaks some buggy clients. Convenience over security.
JMTQp8lwXL
on March 14, 2020
|
parent
[–]
I suppose if having account takeovers is worth the convenience-- sure, it's a tradeoff each company will have to make individually.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: