|
|
|
|
|
by r00fus
2540 days ago
|
|
Thanks - I had no idea that Ubiquiti webapp existed!
How about those internal-by-spec ranges + localhost as "security popup/alert" in major browsers? Or default deny with a popup to allow? I really struggle to see why "legitimate use" that's a minority of all use cases should forbid a consensus from cordoning off a major attack surface with an affordance for that legitimate usage. |
|
Also, legitimate services on the local network have tools like CORS and CSPs as well as standard anti-XSS and anti-CSRF techniques to use to defend themselves.