3 ms·
Apologies about that. There is a TL;DR and an estimated reading time at the top, though. You can also skip the addendum.
by jub0bs 6y ago
Apologies about that. There is a TL;DR and an estimated reading time at the top, though. You can also skip the addendum.
- Noumenon72 6y agoThe tl;dr didn't help me because "the concept of site is difficult to apprehend" doesn't summarize anything. I was looking for a takeaway like "tl;dr -- 'Site' includes other subdomains of your site as cross-domain, while 'Origin' doesn't. Use SameSite=strict for the most safety". If I got that wrong, it's because I didn't finish reading the post. I quit around "what do we mean by 'origin'?" because it was clear there was a lot more background to go and not clear I would learn anything practical.
- jub0bs 6y agoI hoped the TL;DR item entitled "SameSite paints a target on your subdomains' back" would be enough to compel readers to get through the whole post... But I understand your criticism; the post is quite long... By the way, one of the takeaways in the post is that even SameSite=Strict is powerless against (cross-origin) same-site attacks. I would certainly recommend using Strict wherever possible and practical, but Strict shouldn't be misconstrued as a drop-in replacement for anti-CSRF tokens.
- Noumenon72 6y agoThat's still not how I use tl;dr, because it's a teaser, not a summary. I would say "Don't use SameSite=Strict to replace anti-CSRF tokens if you have subdomains". That tells you "Here's what you're going to believe by the end of this article", and then you can decide whether you already know that or care to know.