Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The "unfixable design flaws in the web platform itself" that enable HEIST attack are trivially fixed by disabling third-party cookies, on the client side — in the browser's settings, and on the server side — by using SameSite tag in the Set-Cookie header.

I'm just left wondering why browser vendors don't apply this behavior by default, it would've been much cheaper to fix the broken sites than mitigating the security hell that 3rd-party cookies provide.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: