W3C home > Mailing lists > Public > public-webappsec@w3.org > September 2014

Re: Redirects and HSTS

From: Anne van Kesteren <annevk@annevk.nl>
Date: Fri, 26 Sep 2014 22:09:58 +0200
Message-ID: <CADnb78g4jR2BVdjxM+J74S+KUP54h+BoDyrbMt2KW+2yxydNxA@mail.gmail.com>
To: Ryan Sleevi <sleevi@google.com>
Cc: Mike West <mkwst@google.com>, Tanvi Vyas <tanvi@mozilla.com>, WebAppSec WG <public-webappsec@w3.org>
On Fri, Sep 26, 2014 at 10:07 PM, Anne van Kesteren <annevk@annevk.nl> wrote:
> That does seem to cover it, although the first sentence makes it sound
> more difficult than it really is.

However, could this attack be avoided if we never applied HSTS to
resources loaded from a document on a different origin?

Received on Friday, 26 September 2014 20:10:26 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 18:54:40 UTC