3 ms·
`First, so that the device can protect itself from malicious sites it can provide a set of origins that are allowed to connect to it.` Sounds kinda DRM-ey. The
by fidget 10y ago
`First, so that the device can protect itself from malicious sites it can provide a set of origins that are allowed to connect to it.`
Sounds kinda DRM-ey. The CORS system works because the owner of a URL is the person who can attach headers to responses. That doesn't sound the same in this case, as the owner of a device is the person who owns it, not the manufacturer who decides what metadata it broadcasts (though obviously working out what the UX should be is a hard problem)
- justinschuh 10y agoThis particular restriction is intended to address things like authentication devices (e.g. gnubby) where you basically destroy the entire security model if a user accidentally allows a malicious website to connect to it. That stated, the last round of discussions gave me the impression that browsers generally (and in particular Chrome) are leaning towards implementing this as a very alerting warning rather than an outright block.
- cmrx64 10y agoNote that the policy isn't mandatory. Privileged contexts will likely have access anyway.
- deleted 10y ago[deleted]