3 ms·
If the CSRF token changes with each page view then opening a second page (perhaps an explanation for a form field) in a new tab/window would invalidate the form
by dvogel 13y ago
If the CSRF token changes with each page view then opening a second page (perhaps an explanation for a form field) in a new tab/window would invalidate the form in the original tab/window.
- krapp 13y agoMaybe only have it generated for views of the page with the form on it?
- sehrope 13y agoNot necessarily. The token can be used to simply verify that the request came from a legit page and not cross site request. The encrypted CSRF need only be verified by the server to see if it's not expired. The server can store the expiration in the CSRF token itself (encrypted and signed). It does not need to maintain a list of the CSRF tokens. I wrote about this a little while back. Comments are here: https://news.ycombinator.com/item?id=5971464 https://news.ycombinator.com/item?id=5971464
- dvogel 13y agoWouldn't the lifetime of the token have to be <30 seconds, according to the claims made in the paper?
- sehrope 13y agoI don't think so. Here's the snippet from the linked PDF[1]: > DEFLATE [2] (the basis for gzip) takes advantage of repeated strings to shrink the compressed payload, an attacker can use the the reflected URL parameter to guess the secret one character at a time. By encrypting the CSRF token (or any other "secret" data you want to roundtrip from server to client and back) with a random IV per request this wouldn't work. The value sent by the client would not be the same as the new token generated by the server (since each has a random IV). Even though the decrypted value of each token is the same, the values presented to the client in the response body are each different and not predictable (to the client). [1]: http://breachattack.com/resources/BREACH%20-%20SSL,%20gone%20in%2030%20seconds.pdf http://breachattack.com/resources/BREACH%20-%20SSL,%20gone%2...