Limit HSTS fingerprinting in 1p context #5936
Labels
closed/duplicate
Issue has already been reported
closed/wontfix
priority/P3
The next thing for us to work on. It'll ride the trains.
privacy/tracking
Preventing sites from tracking users across the web
privacy
For #3419, we blocked setting HSTS for third parties.
HSTS fingerprinting can also be achieved in first party context, we should limit setting HSTS headers for the loaded hostname and eTLD+1 similar to: https://webkit.org/blog/8146/protecting-against-hsts-abuse/
The text was updated successfully, but these errors were encountered: