Apple moves on HSTS abuse in Safari

Apple has moved to block an abuse vector in the WebKit framework that underpins its Safari browser and allows HSTS to be abused to act as a ‘supercookie’ for user tracking. HSTS – HTTP Strict Transport Security – allows a Web site to declare to browsers that it’s only accessible via HTTPS.

Read full news article on The Register

 


Date:

Categorie(s):