PLAY PODCASTS
SN166: Cross-Site Request Forgery

SN166: Cross-Site Request Forgery

Security Now - 16k MP3 · TWiT

October 17, 2008

Audio is streamed directly from the publisher (media.grc.com) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.

Show Notes

Leo and I discuss the week's security events, then we address another fundamental security and privacy concern inherent in the way web browsers and web-based services operate: Using "Cross-Site Request Forgery" (CSRF), malicious pranksters can cause your web browser to do their bidding using your authentication.