Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I like the way IRC networks handle this, they use a pre-connection protocol verb called WEBIRC (de-facto standard documented here: http://git.io/vBLYp) that also enforces a whitelist of ip address + password combination. This stops most abuse of this feature. Maybe HTTP servers should have something similar.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: