Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why would it only work if it is the first sign?


Maybe because they were probably already doing sanity checking, but the kind that relied on some previous context? That seems reasonable, I’m sure they’ve thought about this kind of attack before, missing an obscure edge case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: