Jeffrey Yasskin
unread,Nov 5, 2015, 6:04:12 PM11/5/15Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Scott Beardsley, Mike West, Charlie Reis, security-enamel
Redirecting to Enamel for security UI input. Overall:
* The use of noopener to opt into being a secure context isn't related
to the opener.location security hole, so the following comments don't
apply to Mike's stated goals.
* I'm skeptical of an opt-out attribute to plug a security hole.
* I'm skeptical that users can make an informed decision about "allow
the current website to interact with content from another website".
* If the main risk is that the cross-origin opened page will navigate
the opener without the user noticing, any question should appear when
the user's looking at the navigated page, and should just be enough to
alert them that they're now on a different site. If the current use is
low enough, it might make sense to block cross-origin-opener
navigation entirely.
Jeffrey