4 ms·
VU#804060 is talking about "cookie forcing". This is not a new discovery. Here's Chris Evans (not the actor) talking about it in 2008: http://scarybeastsecurity
by agl 11y ago
VU#804060 is talking about "cookie forcing". This is not a new discovery. Here's Chris Evans (not the actor) talking about it in 2008: http://scarybeastsecurity.blogspot.com/2008/11/cookie-forcing.html http://scarybeastsecurity.blogspot.com/2008/11/cookie-forcin...
The best solution is to preload HSTS on a domain and include all subdomains, and we've been saying that for years. That prevents any HTTP connections, although it's obviously not an easy solution in many cases.
The USENIX paper does suggest some unilateral changes to cookie semantics to address this issue, but any such changes have eye-watering compatibility concerns and could only be deployed after a lot of testing.
- chetanahuja 11y ago"The best solution is to preload HSTS on a domain and include all subdomains" That's the great thing about HTTPS/SSL security. Every attack, every vulnerability, every problem with performance is met with "just make sure your server enables XYZ and blah blah blah is updated and make sure the clients are only connecting from chrome while standing on one leg and singing the national anthem while looking at a picture of the Pope. So yeah, it's actually really secure. When are we going to accept that it's a fool's errand. SSL is a hopeless case and design something better for today's world?
- TD-Linux 11y agoWhat do you suppose TLS 1.3 is?
- chetanahuja 11y agoPlease explain how the OP cookie hijacking attack will be mitigated by TLS1.3?
- grey-area 11y agoWe'd all love to see the plan.
- chetanahuja 11y agoHere's one: http://cr.yp.to/tcpip/minimalt-20130522.pdf http://cr.yp.to/tcpip/minimalt-20130522.pdf
- grey-area 11y agoThanks.