Hacker News new | past | comments | ask | show | jobs | submit login

I believe the implication is that you'd have a sessionid. Effectively, the username and password rolled into one unique number, stored in the cookie.



I think by 'specific account' he means 'chosen account', in which case he'd be correct without more targeted social engineering.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: