w3c / w3c/csswg-drafts

[css-values-4] Privacy concern around URL interpolation.

Open
#6,840 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

css-values-5
Dominant language
Bikeshed
Stars
4.9k
Forks
816
PR merge metrics
PR metrics pending

Description

As discussed in CSS fingerprinting, allowing interpolation of variables into URLs will make fingerprinting attacks extremely scalable as it dramatically reduces the large number of requests per user that is required currently - the main limiting factor on the wide-scale adoption of this technique.

I understand that the default position on CSS security is that running untrusted CSS is inherently unsafe (#5092, #2426, #2339), however, I think it would be best to raise this as an issue nonetheless.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the CSS Values 4 URL modifiers section and the linked CSS fingerprinting example. Review the related issues #5092, #2426, and #2339 for the project's existing security position. Done requires a CSS Working Group decision on whether URL interpolation needs a specification change or security guidance.

Written by the indexing model from the issue text.

Assessment

Tech stack
css
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.