4 ms·
It's not that the referer header is not "enough". "Enough" implies that it falls somewhere on the scale of trustworthiness. It's user input. Don't trust user i
by sdevlin 15y ago
It's not that the referer header is not "enough". "Enough" implies that it falls somewhere on the scale of trustworthiness.
It's user input. Don't trust user input.
- eurleif 15y agoWhy shouldn't you trust user-provided data to secure the same user's data? The potential attack is someone forging their own referer header in order to attack themself.
- sdevlin 15y agoThe referer header can easily be forged. The whole point of a CSRF attack is to turn a user's credentials against him.