Skip to content

Commit

Permalink
Update User_Privacy_Protection_Cheat_Sheet.md inclusive/neutral termi…
Browse files Browse the repository at this point in the history
…nology (#1587)

Updated wording to use inclusive/neutral terminology.
  • Loading branch information
ff00ff-security authored Jan 16, 2025
1 parent 3ad4cea commit 78a3902
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion cheatsheets/User_Privacy_Protection_Cheat_Sheet.md
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,7 @@ For more information about anonymity networks, and the user protections they pro

Preventing leakage of user IP addresses is of great significance when user protection is in scope. Any application that hosts external third-party content, such as avatars, signatures or photo attachments; must take into account the benefits of allowing users to block third-party content from being loaded in the application page.

If it was possible to embed 3rd-party, external domain images, for example, in a user's feed or timeline; an adversary might use it to discover a victim's real IP address by hosting it on his domain and watch for HTTP requests for that image.
If it was possible to embed 3rd-party, external domain images, for example, in a user's feed or timeline; an adversary might use it to discover a victim's real IP address by hosting it on their domain and watch for HTTP requests for that image.

Many web applications need user content to operate, and this is completely acceptable as a business process; however web developers are advised to consider giving users the option of blocking external content as a precaution. This applies mainly to social networks and forums, but can also apply to web-based e-mail, where images can be embedded in HTML-formatted emails.

Expand Down

0 comments on commit 78a3902

Please sign in to comment.