Tweet · 25 Feb 2014, 17:11 UTC

Replying to @rodneyrehm

Well, if you don’t use CSRF but accept the likes of cookie auth you deserve whatever comes your way really :)