Re: [whatwg/fetch] From-Origin (#687)

Nit: it's `same-site`, case-sensitive, at least as currently proposed.

The attack can be a little more hidden. The attacker could rewrite the contents of `blog.example` to include a hidden `iframe` for `bank.example` and launch the attack from there while the user is reading `blog.example` (or they could rely on the user not noticing the address bar change and include the contents of `blog.example` on `bank.example`).

It's a fair point that it makes adoption and HTTPS migration trickier though.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/687#issuecomment-393750260

Received on Friday, 1 June 2018 03:52:05 UTC