[saag] Re: Covert Web-to-App Tracking via Localhost

Yakov Shafranovich <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CAAyEnSPrZ082Hc5FQSQj-k-MiYGmfZg0oKV3oVC4_AEh2qWT5w@mail.gmail.com>
Historically the ownership for web related standards was split between
the IETF (HTTP protocols), and other bodies like W3C/WHATWG/CAB. For
this specific issue, there is an IETF RFC defining what a web origin
is (see https://www.rfc-editor.org/info/rfc6454), but what should or
should not be done with the origin in browsers is most likely defined
in the fetch "Living Standard" managed by WHATWG (see
https://github.com/whatwg/fetch). The W3C is also working on privacy
concerns (see https://w3c.github.io/privacy-considerations/).

I would recommend talking to the ADs for the WIT area
(https://datatracker.ietf.org/wg/#WIT), or the liaison for W3C to see
if there is anything for the IETF to do here.

On Wed, Jun 4, 2025 at 4:57 PM Shivan Kaul Sahib
<[email protected]> wrote:
>
> This kind of website-talking-to-localhost attack is nothing new, has been known to Web browsers for decades, and periodically pops up (Zoom, eBay). The only real solution is for browsers to block localhost connections in some sensible way. Brave and Safari do this in varying ways, others don't. I'm not sure if there's an IETF solution here.
>
> On Wed, 4 Jun 2025 at 13:38, Michael Richardson <[email protected]> wrote:
>>
>>
>> John, this "localmess" seems to be about "native" apps that listen on
>> 127.0.0.1, to which mobile browers seem not to filter access, or restrict.
>> Seems very serious to me.
>>
>> (Don't install apps to which one can not review/audit their source code. But,
>> that's never been a IETF responsability)
>>
>>
>> ****
>> I don't see how this an IETF *specific* concern, nor do I see how this is
>> enabled by any current IETF process or policy.
>> ****
>>
>> Maybe we don't need an app for every unique interaction, maybe we need e2e
>> informational models for IoT and the like.  The IETF is already the lead here.
>>
>> John Mattsson <[email protected]> wrote:
>>     > I urge the broader Internet community to reevaluate current approaches,
>>     > and to prioritize user privacy and safety over monetary donations from
>>     > data-hoarding, surveillance-driven tech giants.
>>
>> Except that maybe we shouldn't accept statements like "TLS 1.3 in widely
>> deployed", yet it's only really browsers, and they (browsers) don't seem to
>> support useful TLS features like mutual authentication with 1.3.
>> The HTTP client authentication gap is a problem that seems to be nobody's problem.
>>
>> --
>> Michael Richardson <[email protected]>   . o O ( IPv6 IøT consulting )
>>            Sandelman Software Works Inc, Ottawa and Worldwide
>>
>>
>>
>>
>> _______________________________________________
>> saag mailing list -- [email protected]
>> To unsubscribe send an email to [email protected]
>
> _______________________________________________
> saag mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.