Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Last-modified is just as vulnerable as ETag are since you can set any string as the modified date (it doesn't have to parse as a date) and the browser will replay it

See my comment on the previous thread:

http://news.ycombinator.com/item?id=2825564

I am currently in the midst of writing a browser plugin to block all this bullshit:

http://github.com/nikcub/parley

considering just doing a browser fork since the browsers are so uncooperative.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: