Re: About using CORS

For what it's worth, I don't think this security argument holds much water.
The attacker can always send Access-Control-Allow-Origin:* from their server
to enable cross-site usage. The same-origin check may discourage authors
from linking to other people's sites (which later get compromised or
domain-stolen), thus providing some protection that way, but that's a very
weak argument IMHO.

Rob
-- 
"He was pierced for our transgressions, he was crushed for our iniquities;
the punishment that brought us peace was upon him, and by his wounds we are
healed. We all, like sheep, have gone astray, each of us has turned to his
own way; and the LORD has laid on him the iniquity of us all." [Isaiah
53:5-6]

Received on Tuesday, 4 May 2010 20:32:24 UTC