Тёмный

"A Hipster History of CORS" by Devdatta Akhawe (Strange Loop 2022) 

Strange Loop Conference
Подписаться 83 тыс.
Просмотров 9 тыс.
50% 1

Опубликовано:

 

7 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 7   
@recklessroges
@recklessroges Год назад
Best CORS explanation I've ever seen.
@kesavamallela
@kesavamallela Год назад
Some of the jokes were funny :) also, Go Pilani!
@velociraptor5962
@velociraptor5962 Год назад
This makes so much sense. I still hate CORS though - especially when trying to get data from APIs in web apps. haha
@csours
@csours Год назад
Developers who learn about CORS: "I don't want to learn about CORS, I want my thing to work!" When you learn that CORS exists, it makes no sense. I read about 10 StackOverflow posts about it and 3 articles, and I still didn't understand it. I think it was the 3rd time that I had to deal with it I finally understood that it really doesn't fit my mental model of web security.
@willmcpherson2
@willmcpherson2 Год назад
The web is bandaids 😂
@Verrisin
@Verrisin Год назад
So, can the hacked process access cookies of another origin? I would guess not, so whatever it does doesn't seem too bad ... both CORB and CORP sound useless? What is special about browsers? Cannot the attacker just do that irrespective of a browser? - The point of a browser exploit is, you got inside the local network where I can make requests to servers that think they are behind a wall... - All "secret images" should require Authorization + Authentication anyway, so it's irrelevant some process can make requests, if it doesn't have any secret tokens. - What am I not getting?
@Verrisin
@Verrisin Год назад
Wait ... it can open an anyway, and all of this is EVEN MORE POINTLESS??? What?
Далее
🛑 ты за кого?
00:11
Просмотров 60 тыс.
Первый день школы Катя vs Макс
19:37
ПРОСТИ МЕНЯ, АСХАБ ТАМАЕВ
32:44
Просмотров 2,3 млн
Deterministic Simulation Testing
4:20
Просмотров 376
Ruby on Rails: The Documentary
44:16
Просмотров 251 тыс.
What is CORS?
13:22
Просмотров 65 тыс.
🛑 ты за кого?
00:11
Просмотров 60 тыс.