Chrome ikozvino ichave nekudzivirirwa kubva kune wechitatu-bato makuki uye yakavanzika chitupa

Google yakaunzwa shanduko dziri kuuya kuChrome dzine chinangwa chekuvandudza kuvanzika. Chikamu chekutanga chekuchinja chine chekuita neCookie kubata uye kutsigirwa kweSameSite hunhu. Kutanga nekuburitswa kweChrome 76, inotarisirwa muna Chikunguru, pachava yakamisikidzwa iyo "same-saiti-by-default-cookies" mureza, iyo, kana isipo yeSameSite hunhu muSet-Cookie musoro, inozoisa iyo kukosha "SameSite=Lax", ichidzikamisa kutumira kweMakuki kuti aiswe kubva. yechitatu-bato masaiti (asi mawebhusaiti achiri kukwanisa kudzima kurambidzwa nekunyatso kuseta kukosha SameSite=Hapana kana uchiseta Cookie).

Ipa Zvakafanana inobvumidza iwe kutsanangura mamiriro ayo anotenderwa kutumira Cookie kana chikumbiro chagamuchirwa kubva kune wechitatu-bato saiti. Parizvino, bhurawuza rinotumira Cookie kune chero chikumbiro kune saiti iyo Cookie yakasetwa, kunyangwe imwe saiti yakatanga kuvhurwa, uye chikumbiro chinoitwa zvisina kunanga nekurodha chifananidzo kana kuburikidza neiframe. Manetiweki ekushambadzira anoshandisa chimiro ichi kuteedzera mafambiro evashandisi pakati pesaiti, uye
vanorwisa sangano CSRF inorwisa (kana chishandiso chinodzorwa neanorwisa chikavhurwa, chikumbiro chinotumirwa muchivande kubva pamapeji acho kuenda kune imwe saiti iyo yazvino mushandisi inotenderwa, uye bhurawuza yemushandisi inoseta maCookies ekukumbira kwakadaro). Kune rumwe rutivi, kukwanisa kutumira Cookies kunzvimbo dzechitatu-party inoshandiswa kuisa majeti mumapeji, somuenzaniso, kubatanidzwa neYuoTube kana Facebook.

Uchishandisa hunhu hweSameSit, unogona kudzora maitiro eCookie uye wobvumira maCookies kuti atumirwe chete mukupindura zvikumbiro zvakatangwa kubva kune saiti iyo Cookie yakagamuchirwa pakutanga. SameSite inogona kutora matatu kukosha "Yakasimba", "Lax" uye "Hapana". Mu'Strict' modhi, maCookies haatumirwe kune chero mhando yekuyambuka-saiti zvikumbiro, kusanganisira zvese zvinopinda zvinongedzo kubva kune ekunze masaiti. Mune 'Lax' modhi, zvimwe zvakadzoreredzwa zvirambidzo zvinoiswa uye kufambisa kweCookie kunovharirwa chete kune-yakatarisana-saiti zvikumbiro, senge chikumbiro chemufananidzo kana kurodha zvemukati kuburikidza neiframe. Musiyano uripo pakati pe "Strict" ne "Lax" unosvika pakuvhara maCookies kana uchitevera chinongedzo.

Pakati pedzimwe shanduko dziri kuuya, zvakarongwawo kuisa chirambidzo chakasimba chinorambidza kugadziridzwa kwewechitatu-bato Cookies kune zvikumbiro pasina HTTPS (ine iyo SameSite=Hapana hunhu, Cookies inogona chete kusetwa mune Yakachengeteka mode). Pamusoro pezvo, zvakarongwa kuita basa rekudzivirira kubva pakushandiswa kwechiratidzo chakavanzika ("browser fingerprinting"), kusanganisira nzira dzekugadzira zviziviso zvichibva pane zvisina kunanga data, senge. screen resolution, runyorwa rwemhando dzeMIME dzinotsigirwa, maparamita chaiwo mumisoro (HTTP / 2 ΠΈ HTTPS), kuongororwa kwekuiswa plugins uye mafonti, kuwanikwa kwemamwe maWeb API, chaiwo kumakadhi evhidhiyo maficha kupa uchishandisa WebGL uye Canvas, manipulation neCSS, kuongororwa kwemaitiro ekushanda nawo mouse ΠΈ keyboard.

Zvakare muChrome zvichawedzerwa dziviriro kubva mukushungurudzwa kwakabatana nekunetseka kudzokera kupeji yekutanga mushure mekuenda kune imwe saiti. Tiri kutaura nezve tsika yekuunganidza nhoroondo yekufamba neyakatevedzana yekudzokorodza otomatiki kana kuwedzera zvenhema zvinyorwa munhoroondo yekubhurawuza (kuburikidza nepushState), semhedzisiro iyo mushandisi haakwanise kushandisa bhatani re "Back" kudzokera ku. peji rekutanga mushure mekuchinja netsaona kana kumanikidzwa kutumira kune saiti yevatsotsi kana saboteurs. Kuti udzivirire kubva pamanomano akadai, Chrome iri muBatani reKumashure inosvetuka marekodhi ane chekuita nekutumira otomatiki uye kushandura nhoroondo yekubhurawuza, ichisiya chete mapeji anovhurwa nekuda kwemaitiro emushandisi akajeka.

Source: opennet.ru

Voeg