webappsec.dev

$less ~/slides/securing-web-apps-modern-platform-features

// deck 05 · Google I/O

Securing web apps with modern platform features

Google I/O · Mountain View · 2019· 60 slides· Artur Janc, Lukas Weichselbaum

pdf ↓ 3.1 MB · video

  1. Slide 1: Securing web apps
  2. Slide 2: Google I/O 2019
  3. Slide 3: 1. Common web security flaws
  4. Slide 4: 1. Common web security flaws (continued)
  5. Slide 5 of 60
  6. Slide 6: Google Vulnerability Reward Program payouts in 2018
  7. Slide 7: Injections
  8. Slide 8: Insufficient isolation
  9. Slide 9: Insufficient isolation (continued)
  10. Slide 10: Vulnerabilities by Industry
  11. Slide 11: Vulnerabilities by Industry (continued)
  12. Slide 12: Paid bounties by vulnerability on Mozilla websites in 2016 and 2017
  13. Slide 13: 1. Common web security flaws
  14. Slide 14: 1. Injection defenses 2. Isolation mechanisms
  15. Slide 15: 1. Injection defenses 2. Isolation mechanisms (continued)
  16. Slide 16: Injection defenses:
  17. Slide 17: CSP Basics
  18. Slide 18: Enabling CSP
  19. Slide 19 of 60
  20. Slide 20: Better, faster, stronger:
  21. Slide 21: The Idea Behind Nonce-Based CSP
  22. Slide 22: The Problem of Nonce-Only CSP
  23. Slide 23: Enabler: New strict-dynamic keyword
  24. Slide 24: 1..2..3 Strict CSP
  25. Slide 25: STEP 1: Remove CSP blockers
  26. Slide 26: STEP 1: Remove CSP blockers (continued)
  27. Slide 27: STEP 2: Add <script> nonces
  28. Slide 28: STEP 3: Enforce CSP
  29. Slide 29: CSP Adoption Tips
  30. Slide 30: Detailed guide at
  31. Slide 31: Use the CSP Evaluator
  32. Slide 32: Summary: Nonce-based CSP
  33. Slide 33: Injection defenses:
  34. Slide 34: How does DOM XSS happen?
  35. Slide 35: location.open HTMLFrameElement.srcdoc HTMLScriptElement.InnerText
  36. Slide 36: The idea behind Trusted Types
  37. Slide 37: The idea behind Trusted Types (continued)
  38. Slide 38: The idea behind Trusted Types (continued)
  39. Slide 39: Creating Trusted Types
  40. Slide 40: Trusted Types - default policy
  41. Slide 41: Trusted Types Summary
  42. Slide 42: Try Trusted Types now!
  43. Slide 43: Injection defenses: 2019 edition
  44. Slide 44: 1. Injection defenses 2. Isolation mechanisms
  45. Slide 45: Why do we need isolation?
  46. Slide 46: Why do we need isolation? (continued)
  47. Slide 47: Quick review: origins & sites
  48. Slide 48: Isolation for resources:
  49. Slide 49: Three new HTTP request headers sent by browsers:
  50. Slide 50: GET /foo.png
  51. Slide 51: # Reject cross-origin requests to protect from CSRF, XSSI & other bugs
  52. Slide 52: Adopting Fetch Metadata
  53. Slide 53: Bonus: SameSite cookies
  54. Slide 54: Isolation for windows:
  55. Slide 55: evil.example victim.example
  56. Slide 56: Isolation: Cross-Origin Opener Policy
  57. Slide 57: Adopting COOP
  58. Slide 58: Recap: Web Security, 2019 Edition
  59. Slide 59: CSP3 based on script nonces
  60. Slide 60: Thank you! Helpful resources
1 / 60

// key slides

  1. 62018 bug bounty payouts: XSS alone is 35.6%
  2. 19Gmail's real allowlist CSP, a full page of hosts, struck through
  3. 51A complete Fetch Metadata isolation check in ten lines
  4. 59The recap: all four headers with the exact strings to ship

// what you take away

  • A nonce plus 'strict-dynamic' gives one fixed CSP that blocks injected scripts.
  • Trusted Types make about 60 DOM sinks reject raw strings, ending DOM XSS.
  • Sec-Fetch-Site lets the server reject cross-site requests in ten lines of code.