Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why does this guy think that JWT tokens secure against CSRF? They're unrelated. This scares me. I want to know what projects he works on so I can avoid them. Not knowing something is insecure is one thing, but knowing that it's insecure scares me.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: