Re: [w3ctag/design-reviews] requestStorageAccessForOrigin (Issue #808)

I outlined my (and WebKit's) concerns with this feature in https://github.com/WebKit/standards-positions/issues/125 and https://github.com/privacycg/storage-access/issues/107. If you have two websites A and B. A can ask the user if its requests to B can include the user's cookies for B. All without B's involvement. That's not good for security. It's potentially also bad for B's reputation.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/808#issuecomment-1462158720
You are receiving this because you are subscribed to this thread.

Message ID: <w3ctag/design-reviews/issues/808/1462158720@github.com>

Received on Thursday, 9 March 2023 14:29:38 UTC