Hacker News new | past | comments | ask | show | jobs | submit login

CSRF works the same whether the site is served via HTTP or HTTPS. CSRF attacks the server from the client, so HTTPS doesn't protect from this. HTTPS is an end-to-end encrypted tunnel.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: