You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I've just published a blog post about a technique that allows an active network attacker to observe, from an insecure Web origin, the presence or absence of some Secure cookie that may have been set by the origin’s secure counterpart. Note: It requires a MitM.
Would it make sense to mention this technique somewhere on the wiki? If so, I'm not sure which section...
The text was updated successfully, but these errors were encountered:
Seems for site isolation purposes it is considered cross-site.
It does seem more of a network leak defend-able by enabling "Always use secure connections" in chrome or "HTTPS-Only Mode" in Firefox but still interesting.
I've just published a blog post about a technique that allows an active network attacker to observe, from an insecure Web origin, the presence or absence of some Secure cookie that may have been set by the origin’s secure counterpart. Note: It requires a MitM.
Would it make sense to mention this technique somewhere on the wiki? If so, I'm not sure which section...
The text was updated successfully, but these errors were encountered: