Quantcast
Channel: InformAction Forums
Viewing all articles
Browse latest Browse all 17374

Re: InjectionChecker same-origin policy flaw

$
0
0
This has been deliberated design choice, based on:
  1. The availability of effective countermeasures against MITM attacks like the one you described (HSTS, ForceHTTPS, NoScript's built-in HTTPS options...)
  2. Known false positive issues which would be caused by the stricter policy you're descibing

However I guess I could try to enforce injection checks when landing on HTTPS from a different protocol/port, maybe with an about:config preference switch off, and see how it goes...

Viewing all articles
Browse latest Browse all 17374

Trending Articles