Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

HttpOnly makes it so XSS can't steal your token, but that won't stop XSS from using your token.


True. But XSS stealing your token (which is always possible with localStorage) is still worse than XSS using your token. It's the principle of least privilege all over again.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: