Re: First-Party-Only cookies

Martin Thomson <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <CAPLxc=X_pXF+6WDHVU=sA8ssiHuyBT++3y2zqGS6QdC9beaFzQ@mail.gmail.com>
On Sat, Jan 23, 2016 at 1:33 AM, Mike West <[email protected]> wrote:
> Excluding GET would make that more difficult, but would certainly improve
> security. That's basically why I'm now leaning towards something like
> `SameSite=Lax`, which would allow a stepwise improvement in CSRF protection
> over time.

I can tolerate that.

While the patient is on the table, why not define both labels.
SameSite=Unsafe/All perhaps?
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.