[saag] Re: Covert Web-to-App Tracking via Localhost

Michael Richardson <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
Nico Williams <[email protected]> wrote:
    > purport to support client certificates can only be constrained by the
    > use of trust anchors and they only provide the CN attribute of the
    > certificate's distinguished name (which is totally useless -- SANs are
    > far more useful).

    >> The HTTP client authentication gap is a problem that seems to be
    >> nobody's problem.

    > Ain't that the truth.  Though what the relation to this thread is I
    > don't know.

yeah, sorry for skipping a few steps in my thinking process.

If we had HTTPS *EVERYWHERE*, and that included https://localhost, and mutual
authentication was *ubiquitous*, then when the page attempted to violate the
user's privacy in this way, then the user would get prompted in some way, right?
It would be a major reveal.

The connection is also about understanding that communication security is not
the whole storey.  We also need object security:  Imagine if every single
JSON blob that crossed some (HTTP)API was encrypted *by the browser* (not the
server provided JS) to the intended received.  And the other way too!

    > If we're going to expand this thread to HTTP client authentication...
    > what I most want is an extension that allows clients to figure out how
    > to fetch the [Bearer, like JWT] rocks the servers want.

--
Michael Richardson <[email protected]>   . o O ( IPv6 IøT consulting )
           Sandelman Software Works Inc, Ottawa and Worldwide

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE-----

iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmhBAnUWHG1jcitpZXRm
QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZRfvB/4s+rCUizvURevwtwmXoJlJucaT
ivZVnL/qh2dm0/PEWuWwZB96Uy1KR9S26YLt+YLQD3tn5HYhuBHcZaVhV4/sYRMr
6t63ihz280YJPcEGFUVBT/+MWvmxYA1rNo6CDWX9gq3LgBfn8aGmD9z2HOIm9mWf
mTvvdEYV1iJA+AtV6NDyzx0X1erDVLrwHSMxclmSKaVB3AsgCA3/55SCPUSx7d9H
nxfFb0VqlvhP6frJ7opcBG3FimauTekwAqYcpgkxx0YQ2sGdFbq6ZibUIGbq+DDc
IcuflpQQ4pScnxqW8GLPIoZkWIKoD9uneze9N8nBr57v/LswV889gcqI0yIu
=mOdi
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.