Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It would be nice if web browsers had an option to "only send cookies on HTTPS".

Also: "MEMORY HOLE"? Someone seriously approved that as a code name?



Already available, secure cookies: https://www.owasp.org/index.php/SecureFlag


I am aware of that, and it's not what I'm talking about. That has to be set by the site to be effective.

I'm suggesting a global setting in the browser that means it won't send any cookies to any plain HTTP site, regardless of what the site says.

If enough people enabled an option like this, sites would have to move to HTTPS if they wanted to reliably use cookies, which doesn't seem problematic.


That's a setting for webservers to set on cookies.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: