[Webkit-unassigned] [Bug 186039] Prevent websites from talking to loopback interface (127.0.0.1, localhost)

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Tue May 29 09:23:06 PDT 2018


https://bugs.webkit.org/show_bug.cgi?id=186039

--- Comment #3 from Alexey Proskuryakov <ap at webkit.org> ---
Egor, you keep iterating on how much you want this, and how this used to work for a long time, so several developers came to rely on this feature. No one is going to ignore that. However, user security and privacy is the primary consideration by far.

Also, not sure which CA root risk you are talking about in this context. This issue is about completely blocking loopback access, not about mixed content.

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20180529/ebd08ea2/attachment.html>


More information about the webkit-unassigned mailing list