Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A few days ago, Meldium's announcement of a Ruby gem that provides an inexpensive partial protection (i.e. not disabling gzip) made it to the HN front page:

http://blog.meldium.com/home/2013/8/2/running-rails-defend-y...

The two protective measures are masking the Rails CSRF token and appending a HTML comment to every HTML doc to slow down plaintext recovery. How easy is this to include in a Django plugin?



Is a partial workaround really better than a guaranteed workaround.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: