Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I am guessing that they are able to bypass this restriction.


No, the attack is against SSL and Man-in-the-Middle. They just make the browser send SSL requests with those cookies, and then guess the cookie (sent inside the SSL session).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: