Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider changing the example on the Introduction page #83

Open
arturjanc opened this issue Nov 29, 2020 · 2 comments
Open

Consider changing the example on the Introduction page #83

arturjanc opened this issue Nov 29, 2020 · 2 comments
Labels
improvement Improve parts of an existent article/section

Comments

@arturjanc
Copy link
Contributor

The XS-Leak described in the main example has the drawback of requiring cookies to be present on cross-site resource loads, and at this point both Safari and Chrome don't attach cookies by default.

It could be nice to use an example that works by default in most browsers, but I'm not sure what that could be, because we still want it to be simple and illustrative. Maybe something with a popup?

@terjanq
Copy link
Member

terjanq commented Nov 29, 2020

Good point. We wanted to have as simple example as possible, the popup will increase the complexity significantly. The other example could be Cache-Probing, but I feel that this is also too complex for the introduction section.

I will try to think of a universal example, but I am leaning more towards adding a footnote about same-site lax by default.

@terjanq terjanq added the improvement Improve parts of an existent article/section label Nov 29, 2020
@arturjanc
Copy link
Contributor Author

I think a footnote could be a good compromise here, and it has the benefit of not requiring substantial changes.

If we do this, it may also be nice to mention Safari because they take a different approach but still protect from this specific attack, which is nice.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
improvement Improve parts of an existent article/section
Projects
None yet
Development

No branches or pull requests

2 participants