3 ms·
No, in CSRF the browser is not the adversary, it is a confused deputy, and it’s perfectly reasonable to collaborate with it against the attacker (which is anoth
by FiloSottile 1y ago
No, in CSRF the browser is not the adversary, it is a confused deputy, and it’s perfectly reasonable to collaborate with it against the attacker (which is another site).
You might want to read https://words.filippo.io/csrf https://words.filippo.io/csrf.
- tankenmate 1y agoYou might want to read https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Re...
- nchmy 1y agoYou might want to develop some critical thinking skills. The doc is wrong, and will soon be updated to say that Sec-Fetch-Site is sufficient on its own. https://github.com/OWASP/CheatSheetSeries/issues/1803 https://github.com/OWASP/CheatSheetSeries/issues/1803