130 karma · joined March 27, 2024
That's my blog. I have opinions on software, make a couple of apps and patch other people programs when I like them enough.
People here liked https://smagin.fyi/posts/cross-site-requests/ this post the most.
There are apps and sites that manage to keep the number of cards at min, one is selfridges (not an ad, was just open in another tab), another is firefox settings. MacOS Finder does a good job at grouping things with spacing, and macos generally. iOS seems to put everything on cards, at least nowadays.
Thanks for getting me thinking this way.
So maybe if this post was in less flame-provoking tone I'd suggest trying to add cards back and see if it makes it better. It might, on landings there is a good chance it will.
Why are CSRF tokens rotated? OWASP says it's somehow more secure but I don't really see why.
Another question, does this work with https?
And the third one, if this was the thing some dishonest governments or vpn providers would do this already. Would be cool to read on that (genuinely, not implying this never happened)
depending on why you'are asking the question, * because it decrypts correctly * because it contains some user identifier
People don't usually store sessions in cookies because cookies can't be very big, and session do become big. So what people do instead they store cookies in databases, and put session identifiers into cookies.
Also, one thing I can speculate that phishing would become even easier if such things were allowed
There is little server can do with that, because of the request-based model. The state that persists between requests lives in cookies, and it's browser job not to expose those cookies all around. Turning off single origin policy would be a terrible idea. For one, it makes CSRF work by not allowing cross-origin reads.