Hacker Newsnew | past | comments | ask | show | jobs | submit | valiant's commentslogin

No, to reliably protect your application from cross site request forgery attacks you usually use auth tokens in the request.

So even if there might be a browser-signature based solution for CSRF protection, there is a very solid alternative, which I think is the best practice anyway.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: