4 ms·
Cross-Origin Read Blocking
- arkadiyt 8y agoIf you're interested in cross origin information leaks and defenses against them (including Cross Origin Read Blocking), I highly recommend this short 7 page summary by Artur Janc and Mike West from Google: https://www.arturjanc.com/cross-origin-infoleaks.pdf https://www.arturjanc.com/cross-origin-infoleaks.pdf
- AntonyGarand 8y agoWill we be able to report errors using the upcoming report-to header? I didn't see a report mechanism listed, but like with hpkp and cors I would like those errors to.be reporteable
- colemickens 8y agoDoes anyone have good additional links? I don't understand the risk of delivering an HTML document to. script tag src?
- arkadiyt 8y agoThe risk is via side channel attacks like Spectre. Even if the script fails to execute (since it's html and not javascript), the html document has been loaded into the memory of the process which included the script tag, which can now start reading that memory via side channel attacks.
- h000per 8y agoThis should also help put an end to cross domain search timing attacks. An old example of one using the IMG tag: https://www.idontplaydarts.com/2015/09/cross-domain-timing-attacks-against-lucene/ https://www.idontplaydarts.com/2015/09/cross-domain-timing-a...
- tedunangst 8y agoBut chrome doesn't see the content type until after the response is served.
- untog 8y agoNo, it sees the content type in the headers that are at the start of the response. Presumably if that header isn't correct it'll stop downloading any further data.
- tedunangst 8y agoAfter Lucene has spent some variable amount of time depending on how many documents match the query...
- deleted 8y ago[deleted]