14

http://lists.w3.org

«... CSRF is not a security issue for the Web. A well-designed Web service should be capable of receiving requests directed by any host, by design, with appropriate authentication where needed. If browsers create a security issue because they allow scripts to automatically direct requests with stored security credentials onto third-party sites, without any user intervention/configuration, then the obvious fix is within the browser... »

Full story »
can.axis's picture
Created by can.axis 5 years 47 weeks ago – Made popular 5 years 47 weeks ago
Category: High End   Tags: