Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
0 points
louiskottmann
6mo ago
0 comments
Save
Share
I appreciate that, but in the case of TLS or CSRF tokens the server is not blindly trusting the browser in the way Sec-Fetch-Site makes it.
0 comments
2 comments · 1 top-level
top
newest
oldest
tptacek
6mo ago
· 1 in thread
Sure it is. The same-origin rule that holds the whole web security model together is entirely a property of browser behavior.
louiskottmann
OP
6mo ago
That's indeed a good example of prior full trusting of the browser by the server.
j
/
k
navigate · click thread line to collapse