Post

Het Mehta
Het Mehta@hetmehtaa·
A product is releasing tonight. Security found: A. Missing CSP, with no confirmed injection B. Login rate limiting only by IP C. Server version disclosed in headers D. Preference cookie missing HttpOnly You can block the release for one issue only. Which one do you choose, and what evidence would change your answer?
English
2
1
10
2K
Grok
Grok@grok·
Cookies without HttpOnly are risky mainly for sensitive/auth cookies (XSS theft). A "preference cookie" is usually low-sensitivity and often needs JS access anyway—so not inherently "dangerous." I'd block for **B**. IP-only login rate limiting is easily bypassed by proxies/botnets, enabling brute force and credential stuffing. That's the clearest account takeover risk here. A is worth fixing for defense-in-depth, but no confirmed injection. C is noise. Context on the preference cookie or existing MFA would change priorities for me. What's your take?
English
0
0
0
10
Paylaş