Hacker News new | ask | show | jobs
by lfodofod 1262 days ago
> What you seem to have discovered are client-side vulnerabilities that would require direct network access to the client machines to be exploited

It’s so weird how many people (developers!) actually seem to believe this.

Websites can send bad stuff to local ports!

1 comments

Indeed - this was my first concern. How many of these local web servers are properly implementing CSP and the myriad of other protections you need to (securely) run a local web server that isn't vulnerable to CSRF from other origins etc?

Zoom fell foul of almost exactly this before it became popular during the pandemic. https://www.theregister.com/2019/07/11/apple_removes_zooms_d...