11 ms·
That's how CSRF works - I get you to communicate to the device from your "trusted" smartphone or other device. There is nothing you can do at the routing level
by cmdkeen 9y ago
That's how CSRF works - I get you to communicate to the device from your "trusted" smartphone or other device. There is nothing you can do at the routing level to protect against it. It is entirely up to the endpoint receiving the request to have implemented proper CSRF protection against attacks.
CSRF has been around since 2001 and is in the OWASP top 10. It would be absolutely valid for regulators to require reasonable steps to be taken to prevent its abuse, along with similar attacks.