Preventing CSRF and XSRF Attacks

I want to vote this post up :slight_smile:
not addicted at all…

That is the best explanation I’ve ever read of them.

Amen to mandatory cookies, but there are a whole lot of people out there who have been told that cookies are bad, mmmkay, and just won’t budge. Their brother in law, who knows enough to get their printer unjammed, told them so.

No problem with adding toolbars to their browsers because they get free email smileys though…