RE: Cookies Settings Observations

"Mike O'Neill" <[email protected]>
Newsgroups gmane.org.w3c.tag
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi Mike

Yes, well I was thinking of the third-party who wants to get round (say Safari) third-party cookie blocks to do cross-origin tracking, which isn’t your threat model but is happening and sites may like to avoid it using a CSP type mechanism.

I thought it was worth pointing out that the problem was not just embedded third-party subrequests.

MikeO


From: Mike West [mailto:[email protected]]
Sent: 28 January 2015 13:58
To: Mike O'Neill
Cc: Yehuda Katz; Daniel Appelquist; TAG List
Subject: Re: Cookies Settings Observations

Hi, Mike (this won't get confusing at all! :) )!

On Wed, Jan 28, 2015 at 2:34 PM, Mike O'Neill <[email protected]> wrote:
The browser cannot tell it is “really” a third-party and the user may have no indication they were going to be redirected through the third-party.

What does "really" a third-party mean? In the case you outline, the browser did a full-page navigation to origin X. For that request, origin X is, in fact, the first-party.

The first-party attribute would have to stop cookies being sent in these kind of redirected requests.

1. Why? I think we're dealing with distinct threat models, so I'd like to understand the threat you're trying to defend against. The spec I posted is focused on two:

* It attempts to defend against CSRF attacks that use a user's ambient authority on `https://bank.com/` to do bad things.
* It allows a site that doesn't _want_ to track users cross-origin to set cookies without the risk of receiving them in unexpected circumstances.

2. What kind of heuristics would you suggest? The issue, as you probably understand, is that the browser doesn't know how origin X is going to respond to a request. It may deliver a 200 response with a lovely HTML page. It may deliver a 302 to `https://evil.com/`. It may explode with a 500. It's not clear to me that it's possible to make such an a priori distinction.

- -mike


- --
Mike West <[email protected]>, @mikewest

Google Germany GmbH, Dienerstrasse 12, 80331 München, Germany, Registergericht und -nummer: Hamburg, HRB 86891, Sitz der Gesellschaft: Hamburg, Geschäftsführer: Graham Law, Christine Elizabeth Flores
(Sorry; I'm legally required to add this exciting detail to emails. Bleh.)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.13 (MingW32)
Comment: Using gpg4o v3.4.19.5391 - http://www.gpg4o.com/
Charset: utf-8

iQEcBAEBAgAGBQJUyO7CAAoJEHMxUy4uXm2JvTYIAK73rXBMHrKFLQuSW8ideSL2
pRbOjFUrtbF+RveyRAgzT6IxuyVEO6iMBxYwgkZYpHLC7abjOJYMpsod9DyZ29xi
tLYoroST8GerA9hrc0hiGP88XrN/cZuoSND7TkOw2nl3H4Kq8PKD+y6NNo1/jI4P
jqVEFcvgps2TIjXeDxF0G3oOZUcNCwKSyTHrKFamI93TVcrXnc1KEmysA7IqO+ow
8MYLYYaqpNQm9HWFv5fwXYw+2ogxmHoKD94eN/7sKZALhQsWCKcNuw3LiJGBvriR
FRT1LMhG8jprdQe/pxiAxgsxmqBBKNRr096OJVcOMQ9zsUu+QEfF9nsz+VILKyA=
=Zvok
-----END PGP SIGNATURE-----
PGPexch.htm (text/html, 7.5 KB)
<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta name=Generator content="Microsoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";
	mso-fareast-language:EN-US;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-GB link=blue vlink=purple><div class=WordSection1><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Hi Mike<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Yes, well I was thinking of the third-party who wants to get round (say Safari) third-party cookie blocks to do cross-origin tracking, which isn&#8217;t your threat model but is happening and sites may like to avoid it using a CSP type mechanism. <o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>I thought it was worth pointing out that the problem was not just embedded third-party subrequests.<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>MikeO<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><div style='border:none;border-left:solid blue 1.5pt;padding:0cm 0cm 0cm 4.0pt'><div><div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm'><p class=MsoNormal><b><span lang=EN-US style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b><span lang=EN-US style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'> Mike West [mailto:[email protected]] <br><b>Sent:</b> 28 January 2015 13:58<br><b>To:</b> Mike O'Neill<br><b>Cc:</b> Yehuda Katz; Daniel Appelquist; TAG List<br><b>Subject:</b> Re: Cookies Settings Observations<o:p></o:p></span></p></div></div><p class=MsoNormal><o:p>&nbsp;</o:p></p><div><div><div><p class=MsoNormal>Hi, Mike (this won't get confusing at all! :) )!<o:p></o:p></p></div><div><p class=MsoNormal><o:p>&nbsp;</o:p></p></div><div><p class=MsoNormal>On Wed, Jan 28, 2015 at 2:34 PM, Mike O'Neill &lt;<a href="mailto:[email protected]" target="_blank">[email protected]</a>&gt; wrote:<o:p></o:p></p><p class=MsoNormal>The browser cannot tell it is &#8220;really&#8221; a third-party and the user may have no indication they were going to be redirected through the third-party.<o:p></o:p></p><div><p class=MsoNormal><o:p>&nbsp;</o:p></p></div><div><p class=MsoNormal>What does &quot;really&quot; a third-party mean? In the case you outline, the browser did a full-page navigation to origin X. For that request, origin X is, in fact, the first-party.<o:p></o:p></p></div><div><p class=MsoNormal><o:p>&nbsp;</o:p></p></div><blockquote style='border:none;border-left:solid #CCCCCC 1.0pt;padding:0cm 0cm 0cm 6.0pt;margin-left:4.8pt;margin-right:0cm'><p class=MsoNormal>The first-party attribute would have to stop cookies being sent in these kind of redirected requests.<o:p></o:p></p></blockquote><div><p class=MsoNormal><o:p>&nbsp;</o:p></p></div><div><p class=MsoNormal>1. Why? I think we're dealing with distinct threat models, so I'd like to understand the threat you're trying to defend against. The spec I posted is focused on two:<o:p></o:p></p></div><div><p class=MsoNormal><o:p>&nbsp;</o:p></p></div><div><p class=MsoNormal>&nbsp; &nbsp; * It attempts to defend against CSRF attacks that use a user's ambient authority on `<a href="https://bank.com/%60">https://bank.com/`</a> to do bad things.<o:p></o:p></p></div><div><p class=MsoNormal>&nbsp; &nbsp; * It allows a site that doesn't _want_ to track users cross-origin to set cookies without the risk of receiving them in unexpected circumstances.&nbsp;<o:p></o:p></p></div><div><p class=MsoNormal><o:p>&nbsp;</o:p></p></div><div><p class=MsoNormal>2. What kind of heuristics would you suggest? The issue, as you probably understand, is that the browser doesn't know how origin X is going to respond to a request. It may deliver a 200 response with a lovely HTML page. It may deliver a 302 to `<a href="https://evil.com/%60">https://evil.com/`</a>. It may explode with a 500. It's not clear to me that it's possible to make such an a priori distinction.<o:p></o:p></p></div><div><p class=MsoNormal><o:p>&nbsp;</o:p></p></div><div><p class=MsoNormal>-mike<o:p></o:p></p></div><div><p class=MsoNormal><span style='font-family:"Arial","sans-serif";color:#222222'><br clear=all style='text-align:start;word-spacing:0px'></span><o:p></o:p></p><div><div><div><div><div><p class=MsoNormal style='background:white'><span style='font-family:"Arial","sans-serif";color:#222222'>--<br>Mike West &lt;<a href="mailto:[email protected]" target="_blank"><span style='color:#1155CC'>[email protected]</span></a>&gt;,&nbsp;</span><span style='font-size:9.5pt;font-family:"Arial","sans-serif";color:#222222'>@mikewest</span><span style='font-family:"Arial","sans-serif";color:#222222'><o:p></o:p></span></p></div><div><p class=MsoNormal style='background:white'><span style='font-family:"Arial","sans-serif";color:#222222'><o:p>&nbsp;</o:p></span></p><div><p class=MsoNormal style='background:white'><span style='font-family:"Arial","sans-serif";color:#222222'>Google Germany GmbH, Dienerstrasse 12, 80331 M&#252;nchen, Germany,&nbsp;Registergericht und -nummer: Hamburg, HRB 86891,&nbsp;</span><span style='font-size:9.5pt;font-family:"Arial","sans-serif";color:#222222'>Sitz der Gesellschaft: Hamburg,&nbsp;Gesch&#228;ftsf&#252;hrer: Graham Law, Christine Elizabeth Flores</span><span style='font-family:"Arial","sans-serif";color:#222222'><o:p></o:p></span></p></div><div><p class=MsoNormal style='background:white'><span style='font-family:"Arial","sans-serif";color:#222222'>(Sorry; I'm legally required to add this exciting detail to emails. Bleh.)<o:p></o:p></span></p></div></div></div></div></div></div></div></div></div></div></div></div></body></html>
PGPexch.htm.sig (application/octet-stream, 287 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.