Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Some platforms may have a way to remember a client certificate as a preference, but you can't really bind a certificate to only specific sites.

If you can find a way to abuse a valid authentication to one site in order to gain access to another site, that sounds like a very firmly valid security issue needing investigated.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: