logoalt Hacker News

tptacektoday at 5:30 AM1 replyview on HN

The entire web security model assumes we can trust browsers to implement web security policies!


Replies

louiskottmanntoday at 5:50 AM

I appreciate that, but in the case of TLS or CSRF tokens the server is not blindly trusting the browser in the way Sec-Fetch-Site makes it.

show 1 reply