3 ms·
They are but it's not a problem of the ethereum foundation. Rather, it's a problem of DNS resolvers and browsers.
by tscs37 9y ago
They are but it's not a problem of the ethereum foundation.
Rather, it's a problem of DNS resolvers and browsers.
- tinus_hn 9y agoHaving a service accepting commands with no authorization is a vulnerability. If there are multiple users on the machine they can empty each other’s wallets.
- tscs37 9y agoLocalhost is, to some extend, a trusted context. Additionally this requires not having a password on your wallet.
- tinus_hn 9y agoIn most cases, especially ones like this, that trust is misplaced and dangerous.
- tscs37 9y agoThat's more fault of the browser to allow an untrusted context to access a trusted context while circumventing the usual protections (ie, CORS; SOP)
- tinus_hn 9y agoThese ‘protections’ do not provide a ‘trusted context’ and cannot defend you from another user on the same computer. Now your next mistake will be saying ‘but typically there’s only one user’ which is irrelevant because the system runs services as different users for isolation purposes and this vulnerability ignores this isolation.