3 ms·
Thanks for getting this out so fast! Do you guys have plans to PR these changes back in Rails?
by samhamilton 13y ago
Thanks for getting this out so fast!
Do you guys have plans to PR these changes back in Rails?
- bradleybuda 13y agoYep. I'm sending a patch for the CSRF token masking change shortly. I'm less sure about the length hiding change; it feels like an ugly hack, but we put it in because it's the least awful solution that the paper presents. I'm curious to find out exactly how effective the length hiding is one the PoC code is released.
- StavrosK 13y agoIt will probably make the attack a few orders of magnitude harder, but it'll still be feasible if you don't rate-limit requests.