3 ms·
The article mentions that CSP would be a complete defence against this attack, except that there's a "prefetch trick" that bypasses that defence in Chrome. Coi
by dane-pgp 4y ago
The article mentions that CSP would be a complete defence against this attack, except that there's a "prefetch trick" that bypasses that defence in Chrome.
Coincidentally, last month the Chrome team decided to abandon[0] plans to implement the prefetch-src CSP directive, in favour of a "least-restrictive" directive[1].
The new approach is being tracked on Chrome's feature status website[2], which says: "This allows developer to use resource hints without needing to tweak their content security policy, while giving a tool to prevent exfiltration by having default-src block prefetches."
[0] https://bugs.chromium.org/p/chromium/issues/detail?id=801561 https://bugs.chromium.org/p/chromium/issues/detail?id=801561
[1] https://bugs.chromium.org/p/chromium/issues/detail?id=1406444 https://bugs.chromium.org/p/chromium/issues/detail?id=140644...
[2] https://chromestatus.com/feature/5553640629075968 https://chromestatus.com/feature/5553640629075968