5 ms·
I agree with most of this, but it seems one of the main issues is that it sends it even if autofill is off. I could easily imagine someone overlooking the defau
by xerxesaa 6y ago
I agree with most of this, but it seems one of the main issues is that it sends it even if autofill is off. I could easily imagine someone overlooking the default setting and inadvertently revealing their password.
Also, on what basis is your last statement? There are plenty of scenarios where a subdomain is managed different people, or even different companies. Why should you not trust the root domain if you don't trust the subdomain?
- philliphaydon 6y agoI just re-read the thread and realise I completely missed the bit where auto-fill is sent when turned off. That definitely had to be a bug! In regards to the last statement. It’s much rarer now-days for a sub domain site to be owned outright by someone else where they have logs or a deployed website to capture this information. In fact I honestly cannot think of a subdomain where I can upload my own code to. All the sub domains I can think of are just for multi tenant systems so you have to trust the root domain.
- shakna 6y agoGithub Pages, Netlify, Surge. Wordpress hosts. All of these have very different people controlling the code on the subdomain, than on the root. The root in many cases may actually be trustworthy, but there's no reason to send them credentials that belong with the subdomain.
- SturgeonsLaw 6y agoDynamic DNS hosts could have thousands of subdomains under an individual domain, can be registered for free, and those credentials could get an attacker right into people's home networks. An attacker could hide a bunch of iframes in a page and cover lots of bases in one go.
- manojlds 6y agoIsn't that why sites like GitHub Pages moved to GitHub.io. Any popular service at this point wouldn't be allowing user content on their main domain.
- geofft 6y agoNot only that, but github.io is on the Public Suffix List, which is designed for this purpose. Any site that allows users to run servers or host arbitrary HTML/JS on a subdomain should ensure that the parent domain is on the Public Suffix List, which ensures that one user can't even attack another. (The other problem the Public Suffix List solves is that "foo.co.uk" and "bar.co.uk" shouldn't be treated like "foo.example.com" and "bar.example.com", even though they have the same number of components.)
- yorwba 6y agoTIL https://publicsuffix.org/list/ https://publicsuffix.org/list/
- lioeters 6y agoInteresting - I'd heard about the reasoning for github.io being separate from github.com, to deal with untrusted subdomains. But I didn't know that anyone could register on the Public Suffix List. The submission process is done via a pull request, described here: https://github.com/publicsuffix/list/wiki/Guidelines https://github.com/publicsuffix/list/wiki/Guidelines
- davchana 6y agoCorrect, one example of that subdomain is; ca.gov domain is main domain of California Government, and each department of government have their own sub domain here, often at many levels, dmv.ca.gov, CalCareers.ca.gov, calconnect.ca.gov, dgs.ca.gov. All of these 4 have their own account options & passwords. Chrome displays all options on all domains, but on EXACT match, it just shows username, & shows other sub-domains under username, the ones which doesn't match with current dub domain.