Daily Shaarli
January 7, 2018
"I’m harvesting credit card numbers and passwords from your site. Here’s how.", David Gilbertson (@D__Gilbertson)
I’m harvesting credit card numbers and passwords from your site. Here’s how.
"Due to recently disclosed security vulnerabilities for nearly all computers, you should disable any JavaScript cookie manipulation on your website (e.g. when using the critical CSS technique) by setting your cookies to be SameSite and HttpOnly on the server, as recommended on the Chromium wiki. Otherwise, sensitive data, like session keys, may be exposed to malicious third parties."