by nevster on 3/22/25, 3:15 AM with 13 comments
by bschmidt992 on 3/22/25, 5:07 AM
He seems to think he's cracked "HN's HMAC" but he's confused about why it exists. The HMAC HN requires on comment/story posts is there to protect from CSRF attacks. It's not an anti-bot mitigation since as bschmidt and everyone else knows, it's trivial to automate. It's for CSRF protection: https://owasp.org/www-community/attacks/csrf
by thomassmith65 on 3/22/25, 3:52 AM
by dlivingston on 3/22/25, 3:41 AM
by plasticsoprano on 3/22/25, 3:26 AM
ETA: it’s not a theory, you said it yourself the other day on the wiz post. Also, I’m not Jewish.
by Jtsummers on 3/22/25, 3:16 AM
by bediger4000 on 3/22/25, 3:40 AM
Once a spammer, always a spammer.