Skip to content

"Browsers act as though Cross-Origin-Resource-Policy: cross-origin is set on every response that lacks an explicit CORP header" is not strictly true #3

@enricocarraro

Description

@enricocarraro

Hi Mike,
In a recent discussion @ddworken mentioned that:

This isn't strictly true since a resource without CORP is guaranteed to not be referenced by a page with precise timers (e.g. SharedArrayBuffers). But at the same time, we don't think that this is sufficient to prevent Spectre attacks so the value of this as a defense is somewhat unclear.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions