Cookie Consent by Free Privacy Policy Generator ๐Ÿ“Œ W3C Slaps Down Google's Proposal To Treat Multiple Domains as Same Origin

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š W3C Slaps Down Google's Proposal To Treat Multiple Domains as Same Origin


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: tech.slashdot.org

A Google proposal which enables a web browser to treat a group of domains as one for privacy and security reasons has been opposed by the W3C Technical Architecture Group (TAG). From a report: Google's First Party Sets (FPS) relates to the way web browsers determine whether a cookie or other resource comes from the same site to which the user has navigated or from another site. The browser is likely to treat these differently, an obvious example being the plan to block third-party cookies. The proposal suggests that where multiple domains owned by the same entity -- such as google.com, google.co.uk, and youtube.com -- they could be grouped into sets which "allow related domain names to declare themselves as the same first-party." The idea allows for sites to declare their own sets by means of a manifest in a known location. It also states that "the browser vendor could maintain a list of domains which meet its UA [User Agent] policy, and ship it in the browser." In February 2019, Google software engineer Mike West requested a TAG review and feedback on the proposal was published yesterday. "It has been reviewed by the TAG and represents a consensus view," the document says. According to the TAG, "the architectural plank of the origin has remained relatively steady" over the last 10 years, despite major changes in web technology. It added: "We are concerned that this proposal weakens the concept of origin without considering the full implications of this action." The group identified some vagueness in the proposal, such as whether FPS applies to permissions such as access to microphone and camera. A Google Chrome engineering manager has stated: "No, we are not proposing to change the scope for permissions. The current scope for FPS is only to be treated as a privacy boundary where browsers impose cross-site tracking limitations." But the TAG reckons that the precise scope of FPS should be laid out in the proposal. A second concern is over the suggestion that browser vendors would ship their own lists. "This could lead to more application developers targeting specific browsers and writing web apps that only work (or are limited to) those browsers, which is not a desirable outcome," said the TAG.

Read more of this story at Slashdot.

...



๐Ÿ“Œ W3C Slaps Down Google's Proposal To Treat Multiple Domains as Same Origin


๐Ÿ“ˆ 120.09 Punkte

๐Ÿ“Œ Microsoft slaps down 99 APT35/Charming Kitten domains


๐Ÿ“ˆ 38.78 Punkte

๐Ÿ“Œ Mattermost Desktop App up to 4.3.x Same Origin Policy origin validation


๐Ÿ“ˆ 30.9 Punkte

๐Ÿ“Œ How we treat Covid and Cyber Security the same way


๐Ÿ“ˆ 28.74 Punkte

๐Ÿ“Œ HTTP: Don't treat `localhost` as same host by default


๐Ÿ“ˆ 28.74 Punkte

๐Ÿ“Œ How we treat Covid and Cyber Security the same way


๐Ÿ“ˆ 28.74 Punkte

๐Ÿ“Œ NSA pulls plug on some email spying before Congress slaps it down


๐Ÿ“ˆ 27 Punkte

๐Ÿ“Œ Judge slaps down governmentโ€™s dragnet trawl of 1.3m website users


๐Ÿ“ˆ 27 Punkte

๐Ÿ“Œ FTC slaps down Drizly CEO after 2.4m user records stolen from 'careless' booze app biz


๐Ÿ“ˆ 27 Punkte

๐Ÿ“Œ .new: Google gibt Domains zum Erstellen neuer Inhalte zur Registrierung frei โ€“ das sind die ersten Domains


๐Ÿ“ˆ 25.57 Punkte

๐Ÿ“Œ If I log in to a site using my Google account, is that the same as using the same password on two sites?


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ .Science and .study: Domains of the bookish? More like domains of the JERKS!


๐Ÿ“ˆ 23.57 Punkte

๐Ÿ“Œ Anzeige | Domains registrieren: So kommst du an deine Wunsch-Domains


๐Ÿ“ˆ 23.57 Punkte

๐Ÿ“Œ Anzeige | Domains registrieren: So kommst du an deine Wunsch-Domains


๐Ÿ“ˆ 23.57 Punkte

๐Ÿ“Œ Anzeige | Domains registrieren: So kommst du an deine Wunsch-Domains


๐Ÿ“ˆ 23.57 Punkte

๐Ÿ“Œ Google Chrome up to 48 Blink Same Origin Policy Sandbox privilege escalation


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome 49.0 Blink Same-Origin Policy privilege escalation


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome 49.0 Pepper Plugin Same-Origin Policy privilege escalation


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome 50 DOM Same-Origin Policy privilege escalation


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome 50 Blink V8 Binding Same-Origin Policy privilege escalation


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome up to 51 Same-Origin Policy privilege escalation


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome bis 48 Blink Same Origin Policy Sandbox erweiterte Rechte


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome up to 51 Extensions Same-Origin Policy privilege escalation


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome up to 51 Extension Binding Same-Origin Policy privilege escalation


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome up to 54 on Android Content Renderer Client Same-Origin Policy privilege escalation


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome up to 55 PDF Plugin Same-Origin Policy privilege escalation


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome 49.0 Blink Same-Origin Policy erweiterte Rechte


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome up to 55 Blink Same-Origin Policy privilege escalation


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome up to 1.0.154.43 Same Origin Policy information disclosure


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome 49.0 Pepper Plugin Same-Origin Policy erweiterte Rechte


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome prior 77.0.3865.75 Same Origin Policy privilege escalation


๐Ÿ“ˆ 22.96 Punkte

๐Ÿ“Œ Google Chrome up to 52.x Shared Worker Same-Origin Policy privilege escalation


๐Ÿ“ˆ 22.96 Punkte











matomo