HSTS supercookies are a known fingerprinting vector. This change disallow's third parties from setting security headers: 1. "Strict-Transport-Security" 2. "Expect-CT" 3. "Public-Key-Pins" 4. "Public-Key-Pins-Report-Only" that can be used for fingerprinting. auditors: @diracdeltas, @bbondy, @iefremov
6 lines
133 B
HTML
6 lines
133 B
HTML
<html><head><title>Third Party HSTS</title></head>
|
|
<body>
|
|
<iframe src="/cross-site/c.com/iframe_hsts.html"></iframe>
|
|
</body></html>
|
|
|