- From: Tyler Close <tyler.close@gmail.com>
- Date: Wed, 25 Nov 2009 07:01:14 -0800
- To: HTTP Working Group <ietf-http-wg@w3.org>
The "Security Considerations" section of "HTTP/1.1, part 7: Authentication" should mention that the mechanism is vulnerable to Confused Deputy attacks such as Cross-Site-Request-Forgery (CSRF) and clickjacking. Is someone working on text for this, or should I propose some? See: http://tools.ietf.org/html/draft-ietf-httpbis-p7-auth-08#section-5 --Tyler -- "Waterken News: Capability security on the Web" http://waterken.sourceforge.net/recent.html
Received on Wednesday, 25 November 2009 15:01:56 UTC