Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Good enough for me. Chrome's implementation of partitioned cookies does not work for our use-case, though Firefox's implementation works well. Google has still got some work to do before they go ahead and break everyone's web apps, in my opinion: https://github.com/privacycg/CHIPS/issues/82


One additonal security mechanism you might suggest:

The opener specifically whitelists the embeder's domain in a response header.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: