pull down to refresh
143 sats \ 2 replies \ @k00b OP 16 Jun \ parent \ on: “Localhost tracking” explained. It could cost Meta 32 billion. security
Yep, so clever that it's simple.
Brave browser does prevent this by default, at least this is my understanding. It does seem like a good browser security default would be to block remote sites from calling
localhost
. I am sure there are sites this would break but it could warn you that a site attempted this and allow you to allow it.