[saag] Re: Covert Web-to-App Tracking via Localhost
Yakov Shafranovich <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CAAyEnSPrZ082Hc5FQSQj-k-MiYGmfZg0oKV3oVC4_AEh2qWT5w@mail.gmail.com> |
Historically the ownership for web related standards was split between the IETF (HTTP protocols), and other bodies like W3C/WHATWG/CAB. For this specific issue, there is an IETF RFC defining what a web origin is (see https://www.rfc-editor.org/info/rfc6454), but what should or should not be done with the origin in browsers is most likely defined in the fetch "Living Standard" managed by WHATWG (see https://github.com/whatwg/fetch). The W3C is also working on privacy concerns (see https://w3c.github.io/privacy-considerations/). I would recommend talking to the ADs for the WIT area (https://datatracker.ietf.org/wg/#WIT), or the liaison for W3C to see if there is anything for the IETF to do here. On Wed, Jun 4, 2025 at 4:57 PM Shivan Kaul Sahib <[email protected]> wrote: > > This kind of website-talking-to-localhost attack is nothing new, has been known to Web browsers for decades, and periodically pops up (Zoom, eBay). The only real solution is for browsers to block localhost connections in some sensible way. Brave and Safari do this in varying ways, others don't. I'm not sure if there's an IETF solution here. > > On Wed, 4 Jun 2025 at 13:38, Michael Richardson <[email protected]> wrote: >> >> >> John, this "localmess" seems to be about "native" apps that listen on >> 127.0.0.1, to which mobile browers seem not to filter access, or restrict. >> Seems very serious to me. >> >> (Don't install apps to which one can not review/audit their source code. But, >> that's never been a IETF responsability) >> >> >> **** >> I don't see how this an IETF *specific* concern, nor do I see how this is >> enabled by any current IETF process or policy. >> **** >> >> Maybe we don't need an app for every unique interaction, maybe we need e2e >> informational models for IoT and the like. The IETF is already the lead here. >> >> John Mattsson <[email protected]> wrote: >> > I urge the broader Internet community to reevaluate current approaches, >> > and to prioritize user privacy and safety over monetary donations from >> > data-hoarding, surveillance-driven tech giants. >> >> Except that maybe we shouldn't accept statements like "TLS 1.3 in widely >> deployed", yet it's only really browsers, and they (browsers) don't seem to >> support useful TLS features like mutual authentication with 1.3. >> The HTTP client authentication gap is a problem that seems to be nobody's problem. >> >> -- >> Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) >> Sandelman Software Works Inc, Ottawa and Worldwide >> >> >> >> >> _______________________________________________ >> saag mailing list -- [email protected] >> To unsubscribe send an email to [email protected] > > _______________________________________________ > saag mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]