Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
Firehed
on Oct 15, 2012
|
parent
|
context
|
favorite
| on:
Is it OK to hold credit card numbers in cookies, S...
"Never trust the client"
nessus42
on Oct 16, 2012
[–]
The session information is cryptographically signed, so you don't have to trust it! These stateless server frameworks are just using the client as a state cache.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: