Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Or, use a web browser that doesn’t support any cross site state, at all.

I’d love to have such a browser, and to disable the browser that came with my phone, but does not have this property.

(Things like firefox focus or the duck duck go browser for iOS try to do this; I’m not sure if they succeed, but they should protect against the attack described in the article, at least.)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: