Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
steffenweber
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
The Two Faces of AMP
(timkadlec.com)
4 points
by
steffenweber
9y ago
|
0 comments
2.
▲
Introducing Gnome 3.24: Portland
(help.gnome.org)
3 points
by
steffenweber
10y ago
|
0 comments
3.
▲
SHA-512 is 1.5x faster than SHA-256 on 64-bit platforms
(crypto.stackexchange.com)
123 points
by
steffenweber
10y ago
|
13 comments
4.
▲
by
steffenweber
10y ago
Google should reward fast / jank-free websites instead of rewarding websites that use one particular technology (AMP). On SERPs, both the "flash" icon and the AMP carousel are AMP-exclusive which suggests that Google is abusi
5.
▲
by
steffenweber
10y ago
The conclusion of this discussion seems to be that "SameSite" cookies should be used to help preventing CSRF. https://www.igvita.com/2016/08/26/stop-cross-site-timing-att...
6.
▲
by
steffenweber
10y ago
CSRF protection is not about attacks from evil clients (you can easily spoof any header with the HTTP client library of your choice, of course). CSRF protection is about preventing innocent / well-behaving clients from being tricked in
7.
▲
by
steffenweber
10y ago
If all browsers sent the "Origin" HTTP header [1] with POST requests (such that web applications could rely on it) then CSRF [2] tokens mentioned in the article would become obsolete. You'd just have to check whether the &quo