Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Lots of sites use session cookies. Many don't automatically expire them or rely on browsers to expire them (ex: signed cookies).

Plus rotating the master session key (to force the issue of all users being reset) requires knowing you should do it. By downplaying the issue, CloudFlare is sending the message that customers don't have to do anything.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: