webappsec.dev

$less ~/slides/modern-security-features-for-web-apps

// deck 04 · SecAppDev

Modern Security Features

for web applications

SecAppDev · Leuven · 2023· 75 slides· Lukas Weichselbaum

pdf ↓ 3.9 MB

  1. Slide 1: #SecAppDev Leuven, Belgium 2023
  2. Slide 2: Perennial challenge for ISE: Web security
  3. Slide 3: 1. Common web security flaws
  4. Slide 4: 1. Common web security flaws (continued)
  5. Slide 5: Total Google Vulnerability Reward Program payouts in 2018
  6. Slide 6: A simplified view of web (in)security
  7. Slide 7: Injections
  8. Slide 8: Insufficient isolation
  9. Slide 9: Insufficient isolation (continued)
  10. Slide 10: 1. Common web security flaws
  11. Slide 11: Spoiler
  12. Slide 12: 1. Isolation mechanisms 2. Injection defenses
  13. Slide 13: 1. Isolation mechanisms 2. Injection defenses (continued)
  14. Slide 14: Why do we need isolation?
  15. Slide 15: Why do we need isolation? (continued)
  16. Slide 16: Quick review: origins & sites
  17. Slide 17: Isolation for resources:
  18. Slide 18: Three new HTTP request headers sent by browsers:
  19. Slide 19: GET /foo.png
  20. Slide 20: Fetch Metadata - Resource Isolation
  21. Slide 21: # Reject cross-origin requests to protect from CSRF, XSSI & other bugs
  22. Slide 22: Adopting Fetch Metadata
  23. Slide 23: Detailed guide at
  24. Slide 24: Live Demo
  25. Slide 25: Isolation for windows:
  26. Slide 26: evil.example victim.example
  27. Slide 27: Isolation: Cross-Origin Opener Policy
  28. Slide 28: COOP - Overview
  29. Slide 29: Adopting COOP
  30. Slide 30: Live Demo
  31. Slide 31: XS-Leaks Wiki
  32. Slide 32: Isolation Headers
  33. Slide 33: 1. Isolation mechanisms 2. Injection defenses
  34. Slide 34: Injection defenses:
  35. Slide 35: How does DOM XSS happen?
  36. Slide 36: location.open HTMLFrameElement.srcdoc HTMLScriptElement.InnerText
  37. Slide 37: The idea behind Trusted Types
  38. Slide 38: The idea behind Trusted Types (continued)
  39. Slide 39: Creating Trusted Types
  40. Slide 40: Safe rollouts due to reporting
  41. Slide 41: Trusted Types Summary
  42. Slide 42: Live Demo
  43. Slide 43: Try Trusted Types now!
  44. Slide 44: Injection defenses:
  45. Slide 45: CSP Basics
  46. Slide 46: Enabling CSP
  47. Slide 47: What most people associate with a CSP
  48. Slide 48: Allowlist based CSPs
  49. Slide 49: Why NOT use an allowlist-based CSP
  50. Slide 50: Many allowlist CSP bypasses…
  51. Slide 51: Try the CSP Evaluator to spot
  52. Slide 52: Better, faster, stronger:
  53. Slide 53: Google 2019 Case Study: >60% of XSS Blocked by CSP
  54. Slide 54: The Idea Behind Nonce-Based CSP
  55. Slide 55: The Problem of Nonce-Only CSP
  56. Slide 56: Enabler: New strict-dynamic keyword
  57. Slide 57: 1..2..3 Strict CSP
  58. Slide 58: STEP 1: Remove CSP blockers
  59. Slide 59: STEP 1: Remove CSP blockers (continued)
  60. Slide 60: STEP 2: Add <script> nonces
  61. Slide 61: STEP 3: Enforce CSP
  62. Slide 62: CSP Adoption Tips
  63. Slide 63: CSP Coverage at Google [2019]
  64. Slide 64: CSP Coverage at Google [2023]
  65. Slide 65: Summary: Nonce-based CSP
  66. Slide 66: Live Demo
  67. Slide 67: Detailed guide at
  68. Slide 68: Injection defenses: 2023 edition
  69. Slide 69: Recap: Web Security, 2023 Edition
  70. Slide 70: CSP3 based on script nonces
  71. Slide 71: Browser Support 🤔
  72. Slide 72: It all starts with a header..
  73. Slide 73: Bonus Slides
  74. Slide 74: Preventing Prototype Pollution for the Industry
  75. Slide 75: Thank you! Helpful resources
1 / 75

// key slides

  1. 49More than 95% of allowlist CSPs on the web are bypassable
  2. 53Google 2019: CSP blocked 78% of XSS on the most sensitive domains
  3. 64CSP at Google in 2023: 85% of traffic, 300+ domains, 700+ services
  4. 68The injection defense stack, and the apps with zero XSS

// what you take away

  • Allowlist CSPs fail: tools bypass more than 95% of them automatically.
  • 100+ Google apps enforce nonce CSP plus Trusted Types and had no XSS in 2021.
  • Fetch Metadata lets the server reject cross-site requests in a few lines.