Security/Cookies: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
(add work in progress and research)
(→‎Existing functionality: add network.cookie.thirdparty.nonsecureSessionOnly)
 
(5 intermediate revisions by the same user not shown)
Line 27: Line 27:
** https://dxr.mozilla.org/mozilla-central/rev/85cf2e720a8405c43eabc9b34cce381b66d25ef9/netwerk/cookie/nsCookieService.cpp#3794-3816
** https://dxr.mozilla.org/mozilla-central/rev/85cf2e720a8405c43eabc9b34cce381b66d25ef9/netwerk/cookie/nsCookieService.cpp#3794-3816
** not exposed anywhere
** not exposed anywhere
* <tt>network.cookie.thirdparty.nonsecureSessionOnly</tt>
** for those third-party cookies set over HTTP, only accept them for this session
** https://bugzilla.mozilla.org/show_bug.cgi?id=1160368
* per-site third-party cookie blocking
* per-site third-party cookie blocking
** https://wiki.mozilla.org/Privacy/Features/Per-Site_Third-Party_Cookie_Setting
** https://wiki.mozilla.org/Privacy/Features/Per-Site_Third-Party_Cookie_Setting
Line 50: Line 53:
== Specifications ==
== Specifications ==


* Proposals to revise RFC6265: https://lists.w3.org/Archives/Public/ietf-http-wg/2015OctDec/0165.html
* RFC6265bis: https://datatracker.ietf.org/doc/draft-ietf-httpbis-rfc6265bis/
** https://lists.w3.org/Archives/Public/ietf-http-wg/2015OctDec/0165.html
* Cookie prefixes: https://tools.ietf.org/html/draft-ietf-httpbis-cookie-prefixes-00
* Cookie prefixes: https://tools.ietf.org/html/draft-ietf-httpbis-cookie-prefixes-00
* <s>Cookie control in CSP: https://w3c.github.io/webappsec-csp/cookies/</s> (abandoned)
* <s>Cookie control in CSP: https://w3c.github.io/webappsec-csp/cookies/</s> (abandoned)
Line 64: Line 68:


* Changes coming to Chrome: https://groups.google.com/a/chromium.org/forum/#!topic/security-dev/2PK3q_VE1rg/discussion
* Changes coming to Chrome: https://groups.google.com/a/chromium.org/forum/#!topic/security-dev/2PK3q_VE1rg/discussion
** leave-secure-cookies-alone: https://code.google.com/p/chromium/issues/detail?id=546820 and https://groups.google.com/a/chromium.org/d/topic/blink-dev/g_igIzSue40/discussion
** <s>leave-secure-cookies-alone:
** <s>cookie-prefixes: https://code.google.com/p/chromium/issues/detail?id=541511 and https://groups.google.com/a/chromium.org/d/topic/blink-dev/ueCrrgFX8J4/discussion</s>
*** https://bugzilla.mozilla.org/show_bug.cgi?id=976073
*** https://code.google.com/p/chromium/issues/detail?id=546820
*** https://groups.google.com/a/chromium.org/d/topic/blink-dev/g_igIzSue40/discussion</s>
** <s>cookie-prefixes:
*** https://code.google.com/p/chromium/issues/detail?id=541511
*** https://groups.google.com/a/chromium.org/d/topic/blink-dev/ueCrrgFX8J4/discussion</s>
** <s>same-site cookies: https://code.google.com/p/chromium/issues/detail?id=459154</s>
** <s>same-site cookies: https://code.google.com/p/chromium/issues/detail?id=459154</s>
* Prior work in Firefox: https://wiki.mozilla.org/SecurityEngineering/ThirdPartyCookies
* Prior work in Firefox: https://wiki.mozilla.org/SecurityEngineering/ThirdPartyCookies
** expression of interest: https://groups.google.com/d/msg/mozilla.dev.platform/yEqC74IgnqQ/wIVQh4W2EAkJ
** expression of interest: https://groups.google.com/d/msg/mozilla.dev.platform/yEqC74IgnqQ/wIVQh4W2EAkJ
** same-site cookies: https://bugzilla.mozilla.org/show_bug.cgi?id=795346
** <s>same-site cookies: https://bugzilla.mozilla.org/show_bug.cgi?id=795346</s>
** third-party cookie blocking:
** third-party cookie blocking:
*** original patch: http://webpolicy.org/2013/02/22/the-new-firefox-cookie-policy/
*** original patch: http://webpolicy.org/2013/02/22/the-new-firefox-cookie-policy/

Latest revision as of 08:52, 26 April 2018

Existing functionality

Further work

Specifications

Work in progress

Research