Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

do you know of any particular reason that wasn't put in to place years ago? concern for legacy browsers at all costs? it sounds snarky, but it's a genuine question - I think I've set my apps to be http-only cookies for a while now, and am wondering why someone would only get around to it in 2014.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: