Later archive addition
CSP fingerprinting with same-origin redirects
The article shows that Firefox's handling of same-origin redirects under Content Security Policy leaks whether a target URL redirects. By embedding carefully chosen resources and observing policy outcomes, an attacker can fingerprint authenticated application state and other redirect-dependent information across origins.
Record
- Researcher
- やっていく気持ち and @lmt_swallow
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of やっていく気持ち and @lmt_swallow, first published at the original source. Preserved copies are kept so the citation survives its host.