LavaMoat / snow

Use Snow to finally secure your web app's same origin realms!
https://lavamoat.github.io/snow/demo/
MIT License
100 stars 9 forks source link

Can you bypass Snow 2? 🎉 #130

Closed weizman closed 11 months ago

weizman commented 1 year ago

This isn't really an issue, more of an invite to hack Snow again!

Snow 2 ❄️

Your time is precious being highly talented figures, so I'd understand if you can't - but I invite you to give bypassing Snow another crack, with the hope that v2 is better secured.

Tagging former Snow security contributors @mmndaniel @arxenix @NDevTK @magicmac @rwaldron @benjamingr @naugtur @mhofman (thank you for your help so far ❤️ sorry if I forgot anyone)

Clarifications

  1. Snow 2 solves all former issues (hopefully) which is why almost all of them are marked as "closed"
  2. One issue that isn't fully addressed yet is #73 by @magicmac which is inertially more complicated and is being thought of @ #122
weizman commented 1 year ago

@benjamingr @ https://github.com/LavaMoat/snow/issues/129#issuecomment-1640046142

Found it, working on a fix

weizman commented 1 year ago

131 fixed, thank you @benjamingr 🙏

weizman commented 11 months ago

Snow 2 was a mistake #133