Re: SOP-Bypass-Mini-Test-Suite

2016-07-12 Thread Matt Wobensmith
Hi Jordan, Thanks so much for bringing this to our attention. I went through the test suite on both desktop Firefox and mobile Fennec. I did not see any failures. The tests can be confusing. For instance, test 8 has alert boxes with a message that indicates it might have failed. However, a close

Re: SOP-Bypass-Mini-Test-Suite

2016-07-11 Thread Michael Comella
Hey Jordan. Thanks for the feedback – I'll pass this on to Matt, who's on the security team. - Mike (:mcomella) On Sat, Jul 9, 2016 at 6:06 AM, Jordan Johnston wrote: > Hi, > > Recently, I watched a blackhat conference talk on youtube entitled > "Bypassing Browser Security Policies For Fun And