2 ms·
This is a continuation of a long arc of convergent work [1][2][3][4][5] by various people over several years; I've been following along [6]. The innovation of
by niftich 7y ago
This is a continuation of a long arc of convergent work [1][2][3][4][5] by various people over several years; I've been following along [6].
The innovation of this proposal is to work towards the crossdomain cookie transmission being less insecure-by-default, by eventually making the current, limitless behavior opt-in.
This shifts the incentive of developers: presumably those whose sites require crossdomain acceptance of cookies will modify their sites accordingly, while those whose sites don't, or those who haven't thought about the issue will see fewer incidences of the most egregious POST-based CSRF.
[1] https://www.microsoft.com/en-us/research/publication/atlantis-robust-extensible-execution-environments-for-web-applications/ https://www.microsoft.com/en-us/research/publication/atlanti...
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=795346 https://bugzilla.mozilla.org/show_bug.cgi?id=795346
[3] https://github.com/mozmark/SameDomain-cookies/blob/master/samedomain.txt https://github.com/mozmark/SameDomain-cookies/blob/master/sa...
[4] http://homakov.blogspot.com/2013/02/rethinking-cookies-originonly.html http://homakov.blogspot.com/2013/02/rethinking-cookies-origi...
[5] https://tools.ietf.org/html/draft-west-first-party-cookies-07 https://tools.ietf.org/html/draft-west-first-party-cookies-0...
[6] https://news.ycombinator.com/item?id=13689697#13691022 https://news.ycombinator.com/item?id=13689697#13691022