|
|
|
|
|
by buu700
2848 days ago
|
|
This sounds like pretty much the same argument that @eganist and I made to Google and Mozilla a little while back before demoing an HPKP supercookie (https://github.com/cyph/hpkp-supercookie) at Black Hat and DEF CON. Our position was that doing just about anything less than what Chris did here was essentially lying to users about incognito mode's threat model, but if I recall correctly both teams viewed other security tradeoffs (such as carrying over HPKP and HSTS state) as worth considering infringing on incognito's stated purpose. In the end they did both follow our suggested mitigation for the HPKP issue (before Google turned around and deprecated HPKP out of nowhere ಠ_ಠ), but it isn't surprising to hear that similar issues may still exist. |
|