vulny.app on Nostr: "Cookies are encrypted over HTTPS, so they're safe." HTTPS protects them in transit, ...
"Cookies are encrypted over HTTPS, so they're safe." HTTPS protects them in transit, not from a script on your own page. HttpOnly is what keeps client-side JavaScript from reading the session token.
#cybersecurity #infosec #nostr #appsec #owasp
Published at
2026-07-04 01:11:00 UTCEvent JSON
{
"id": "45a5a168a372e0ef8656d9b8b88a066b5d1ba1a71a0991e06aa3cda1e3bab8aa",
"pubkey": "e2eeb88c6504795805452b4e1a1db731dfea087aa7d0ac3e48efbaf0ee416c9d",
"created_at": 1783127460,
"kind": 1,
"tags": [
[
"t",
"cybersecurity"
],
[
"t",
"infosec"
],
[
"t",
"nostr"
],
[
"t",
"appsec"
],
[
"t",
"owasp"
]
],
"content": "\"Cookies are encrypted over HTTPS, so they're safe.\" HTTPS protects them in transit, not from a script on your own page. HttpOnly is what keeps client-side JavaScript from reading the session token.\n\n#cybersecurity #infosec #nostr #appsec #owasp",
"sig": "904a844bc95487bcd3b5dff95f48525ed1c23fa023978da642815fe5b6eadebfe5ddfa67fcbea5210cee00724d04916309cc96018c1018a1600e61ee3752112a"
}