Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin

This reminds me of some vague memories of a time long ago where some websites had a secure login page that asks for a username&pw but every other page after just checked the referall header. It wasn't a very secure system and people shared the header values needed to bypass logging in.


That's basically a degenerate form of capability-based security. Sharing the referrer header is delegating access rights. Of course, that's not actually a property you want in this case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: