HN
Hacker News
Top
New
Best
Ask
Show
Jobs
Comment by mollmerx | Hacker News Reader
Parent
Full thread
mollmerx
·
The passwords are generated on the client.
View on HN
rnhmjoj
·
What if someone is listening to your traffic and injects a script which sends generated passwords to a server? http only is a bad idea in this case.
Reply on news.ycombinator.com