3 ms·
The user couldn't be signed in as the attacker if search.com required their cookie to be signed. Only search.com would have the secret key. EDIT: Just read h
by techscruggs 11y ago
The user couldn't be signed in as the attacker if search.com required their cookie to be signed. Only search.com would have the secret key.
EDIT: Just read https://news.ycombinator.com/item?id=10279794 https://news.ycombinator.com/item?id=10279794 ... NM, you are correct.