Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Protect your reset password tokens: UK Data Protection position on referers
(opens in new tab)
(iconewsblog.wordpress.com)
1 points
fastmark
10y ago
1 comments
Save
Share
1 comments
1 comments · 1 top-level
top
newest
oldest
fastmark
OP
10y ago
If you wish to use Reset Password tokens, then be sure to block referers and/or not include any third party loaded assets (JavaScript, css, etc).
It's not just reset password tokens: beware any protected data, like PII (emails, etc)!
j
/
k
navigate · click thread line to collapse