Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Cookies were invented at Netscape like 25 years ago, nobody considered the current situation.


Yes they did. It was foreseen, look at the sibling comment where the issue was discussed in the spec. They just punted, just like they did with https and CAs. (And Javascript, for that matter, although that's less directly security-related.)

The concern was being first to market, not with solid engineering.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: