3 ms·
Missing 1. Content security policy headers for web 2. "strict" Samesite cookie flags for CSRF and authentication tokens Difference of opinion Didn't argon2
by zallarak 9y ago
Missing
1. Content security policy headers for web
2. "strict" Samesite cookie flags for CSRF and authentication tokens
Difference of opinion
Didn't argon2 win the last password hashing competition?
- zallarak 9y agoJust curious - why the downvote?
- jlgaddis 9y agoAt a guess, it might be because the things that you say are "missing" are specific to HTTP, yet the document says nothing (that I remember) about HTTP at all. The recommendations being discussed in the article are at a completely different level. It's like if I said, "you forgot to mention to disable root logins via SSH". While that might certainly be a good recommendation, it's out of scope as it has nothing to do with what is being discussed.
- zallarak 9y agoAh, thank you. I fully understand now the stupidity of my response. The title itself says "cryptographic" in it, and my answers had nothing to do with that. My mistake.