Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.
Sign upPipeline ID spoofing when iframes create pipeline ids? #10885
Closed
Labels
Comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
We are thinking about how to make pipeline ids unguessable, so that even if an attacker compromises their own pipeline, they can't escalate to compromise other ones by spoofing pipeline ids in requests to the constellation.
We need to think about #7807 in this context: can an attacker navigate to
alice.com, but generate the pipeline id for Alice and then spoof the constellation?IRC discussion with @Manishearth and @jdm at http://logs.glob.uno/?c=mozilla%23servo&s=27+Apr+2016&e=27+Apr+2016#c416685.