Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I imagine you realize that a user under MITM would have the report POST request tampered? It's false security.

On the other hand, you are right that the crawler wouldn't catch everything.



I'm not certain what the implementation status is in various browsers, but the relevant RFCs (e.g. for HPKP) typically recommend that user agents retry the submission of reports. The report URIs themselves may also use HPKP to prevent them from being intercepted (as opposed to just DoSing the submission). There are certainly scenarios where an attacker can only temporarily MitM the victim and the reporting mechanism would still be of use eventually. The reporting itself is not the enforcing mechanism, so timely submission is not the most important thing in the event of an attack.

That said, it's true that the biggest practical use people get out of report-uri is to test the roll-out of these headers and to detect issues they might cause.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: