New issue
Advanced search Search tips

Issue 754395 link

Starred by 0 users

Issue metadata

Status: Fixed
Owner:
Closed: Aug 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 2
Type: Bug

Blocking:
issue 615413



Sign in to add a comment

Disregard Alternative Service information in response if connection has certificate errors

Project Member Reported by b...@chromium.org, Aug 10 2017

Issue description

This is a spinoff from https://crbug.com/615413#c25.  The security concern here is that an on-path attacker (e.g. public WiFi network operator) can proxy traffic with a self-signed certificate to inject AltSvc headers (or ALTSVC HTTP/2 frames) that will persist on the client's device and allow the connection to be hijacked even afterwards when the device is on an uncompromised network.
 

Comment 1 by b...@chromium.org, Aug 10 2017

Blocking: 615413

Comment 2 by b...@chromium.org, Aug 14 2017

Components: Internals>Network>HTTP2

Comment 3 by b...@chromium.org, Aug 30 2017

Summary: Disregard Alternative Service information in response if connection has certificate errors (was: Disregard Alternative Service information in response if certificate is self-signed)

Comment 5 by b...@chromium.org, Aug 30 2017

Status: Fixed (was: Started)

Sign in to add a comment