logoalt Hacker News

toomuchtodoyesterday at 8:25 PM1 replyview on HN

Is there no browser setting to defend against this attack? If not, there should be, versus relying on extension authors to configure or enable such a setting.


Replies

zahlmanyesterday at 8:44 PM

I imagine that it would require browsers to treat web requests from JS differently from those initiated by the user, specifically pretending the JS-originating requests are by logged-out or "incognito" users (by, I suppose, simply not forwarding any local credentials along, but maybe there's more to it than that).

Which would probably wreak havoc with a lot of web apps, at least requiring some kind of same-origin policy. And maybe it messes with OAuth or something. But it does seem at least feasible.

show 1 reply