coates’s avatarcoates’s Twitter Archive—№ 2,086

  1. Explaining that clickjacking is not CSRF: they just look similar. Example: http://twitter.com/home?status=foo+bar