3 ms·
> Wouldn't an attacker just use an older browser that doesn't support 'SameSite' to launch a CSRF attack? With a CSRF attack, it's the victim's browser perform
by Aaron1011 10y ago
> Wouldn't an attacker just use an older browser that doesn't support 'SameSite' to launch a CSRF attack?
With a CSRF attack, it's the victim's browser performing the request - which the attack doesn't have control over.
> I feel like I'm missing something but relying on the browser to protect your site is leaving yourself wide open.
Sites can just add in the 'SameSite' attribute in addition to whatever CSRF mitigation measure they use.