[saag] Re: Covert Web-to-App Tracking via Localhost
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Nico Williams <[email protected]> wrote: > purport to support client certificates can only be constrained by the > use of trust anchors and they only provide the CN attribute of the > certificate's distinguished name (which is totally useless -- SANs are > far more useful). >> The HTTP client authentication gap is a problem that seems to be >> nobody's problem. > Ain't that the truth. Though what the relation to this thread is I > don't know. yeah, sorry for skipping a few steps in my thinking process. If we had HTTPS *EVERYWHERE*, and that included https://localhost, and mutual authentication was *ubiquitous*, then when the page attempted to violate the user's privacy in this way, then the user would get prompted in some way, right? It would be a major reveal. The connection is also about understanding that communication security is not the whole storey. We also need object security: Imagine if every single JSON blob that crossed some (HTTP)API was encrypted *by the browser* (not the server provided JS) to the intended received. And the other way too! > If we're going to expand this thread to HTTP client authentication... > what I most want is an extension that allows clients to figure out how > to fetch the [Bearer, like JWT] rocks the servers want. -- Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE----- iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmhBAnUWHG1jcitpZXRm QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZRfvB/4s+rCUizvURevwtwmXoJlJucaT ivZVnL/qh2dm0/PEWuWwZB96Uy1KR9S26YLt+YLQD3tn5HYhuBHcZaVhV4/sYRMr 6t63ihz280YJPcEGFUVBT/+MWvmxYA1rNo6CDWX9gq3LgBfn8aGmD9z2HOIm9mWf mTvvdEYV1iJA+AtV6NDyzx0X1erDVLrwHSMxclmSKaVB3AsgCA3/55SCPUSx7d9H nxfFb0VqlvhP6frJ7opcBG3FimauTekwAqYcpgkxx0YQ2sGdFbq6ZibUIGbq+DDc IcuflpQQ4pScnxqW8GLPIoZkWIKoD9uneze9N8nBr57v/LswV889gcqI0yIu =mOdi -----END PGP SIGNATURE-----