Episode 126 - Will the New Chrome version 80 finally end Cross-Site Request forgery?

The Backend Engineering Show with Hussein Nasser

Episode | Podcast

Date: Tue, 04 Feb 2020 22:09:44 GMT

<p>Google just released the latest version of Chrome (80) and one of the interesting features making a big change to the default cookies that might actually prevent CSRF forever. Let’s discuss this. &nbsp;&nbsp;#softwarenews &nbsp;*</p> <p><br /></p> <p>&nbsp;Same Site Attribute * Break some apps * Devs must explicitly set None;secure * Will this end CSRF&nbsp;</p> <p><br /></p> <p>&nbsp;&nbsp;Resources &nbsp;https://youtu.be/GPz7onXjP_4&nbsp;</p> <p>https://www.chromestatus.com/feature/5088147346030592 &nbsp;&nbsp;</p> <p><br /></p> <p>News Theme 2&nbsp;by&nbsp;Audionautix&nbsp;is licensed under a&nbsp;Creative Commons Attribution&nbsp;license (https://creativecommons.org/licenses/by/4.0/) Artist:&nbsp;http://audionautix.com/</p>