Simon Willison’s Weblog

Subscribe

Entries tagged google, csrf

Filters: Type: entry × google × csrf × Sorted by date


Fighting RFCs with RFCs

Google’s recently released Web Accelerator apparently has some scary side-effects. It’s been spotted pre-loading links in password-protected applications, which can amount to clicking on every “delete this” link — bypassing even the JavaScript prompt you carefully added to give people the chance to think twice.

[... 353 words]

Types

Years

Tags