Re: Migrating "A Well-Known URL for Changing Passwords" to WebAppSec from WICG


> I am also concerning that draft is not considering 3rd level domains
> take over and how an attacker could advertise a password change URL to
> get a Beef kind of hooking of clients in a bot fashion.

Would changing the spec to always use the registrable domain in the URL
address your concern?

I've filed to
track this.


Received on Wednesday, 6 May 2020 13:44:09 UTC