> Twitter allowing updates through the API via IFRAMES and GET
Total amateurs. I hope those guys didn't have the guts to say anything about diaspora. Because disallowing GET updates is, like, third page on network security book.
Total amateurs. I hope those guys didn't have the guts to say anything about diaspora. Because disallowing GET updates is, like, third page on network security book.
The article is also subtly wrong. GET requests can be protected from CSRF attacks. There just isn't ever a reason to do that if you're doing things right.
2. You're arguing about semantics. CSRF is a security issue. Being able to send updates without user's knowledge is a security hole too. Backed up by a wrong behaviour if you wish. I should never forget that HN is a Serious Business.
None of the above mentioned makes twitter guys any less lame.