TE
TechEcho
Home
24h Top
Newest
Best
Ask
Show
Jobs
English
GitHub
Twitter
Home
Protect your reset password tokens: UK Data Protection position on referers
1 points
by
fastmark
over 9 years ago
1 comment
fastmark
over 9 years ago
If you wish to use Reset Password tokens, then be sure to block referers and/or not include any third party loaded assets (JavaScript, css, etc).<p>It's not just reset password tokens: beware any protected data, like PII (emails, etc)!