Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Never trust the client"


The session information is cryptographically signed, so you don't have to trust it! These stateless server frameworks are just using the client as a state cache.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: