Connect with us

Business

Firefox becomes latest browser to support Fetch Metadata request headers

Published

on

Firefox now supports Fetch Metadata request headers, Mozilla has announced, further protecting users from a number of high-impact web attacks.

The new version of the popular browser, which was made available to all users today, is the latest to include the Google-developed privacy feature.

In total, Firefox 90 will feature four different headers – Dest, Mode, Site, and User – which together allow web applications to protect users against various cross-origin threats, including cross-site request forgery (CSRF), cross-site leaks (XS-Leaks), and Spectre-style side-channel attacks.

blog post released today (July 13) contains more information about Mozilla’s implementation of the technology.

Timeline

Fetch Metadata request headers were introduced in Chrome 76, which was released in July 2019.

The headers provide web servers with extra security information that can help determine whether to block or allow requests.

They also allow a user to deploy a Resource Isolation Policy, a strong defense-in-depth mechanism.

This not only helps protect users from the potentially harmful attacks listed above, but can also help web servers to differentiate between cross-site and same-origin requests.

Fetch Metadata request headers are already available for Edge and Opera, which are also based on the open source Chromium framework.

To find out more about how Fetch Metadata request headers work, check out this interview with Lukas Weichselbaum, staff information security engineer at Google, who spoke to The Daily Swig about the technology.

Source: https://portswigger.net/daily-swig/firefox-becomes-latest-browser-to-support-fetch-metadata-request-headers

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO