3 ms·
.
by yuy7878 6y ago
.
- laszlokorte 6y agoSome people like their sites to work with out javascript.
- deepersprout 6y ago> Some people like their sites to work with out javascript. The 2020 solution to CSRF attacks is using `SameSite` cookies. That makes CSRF tokens obsolete. So if you can accept that old browsers may be vulnerable, you can just use `SameSite` cookies and be done with it.
- segfaultbuserr 6y agoCSRF itself is nothing new. What's different here is a discussion of CSRF-generation techniques that are immune to CRIME and BEAST attacks (which are two related, somewhat unpatchable cryptographic attacks that exploits compression to leak information using a chosen-plaintext attack), which is not something people often talk about.
- dgoldstein0 6y agoAnother solution is to set the csrf token as two cookies: one that can be read by js via document.cookie, and another that is httponly. Js is then responsible for including the csrf token in any requests (including forms). This avoids crime/breach issues because cookies are part of http headers, which are "compressed" with hpack in http2. Hpack is basically "send it once and reference the last value many times". Of course there are a few more details to getting this right (such as tying csrf & auth cookies) and it doesn't hurt to also add samesite to the mix.