Are CSRFs Still a Thing?

What SameSite by default means for the future of CSRFs

Vickie Li
Better Programming
Published in
3 min readAug 26, 2020

--

Photo by Mak on Unsplash.

CSRF vulnerabilities happen when attackers can initiate forged state-changing requests from a foreign domain. This usually occurs because the user’s browser sends session cookies regardless of where the request originates from.

--

--

Professional investigator of nerdy stuff. Hacks and secures. Creates god awful infographics. https://twitter.com/vickieli7