Web Hack List

Later archive addition

Language-based Defenses Against Untrusted Browser Origins

Script components sharing a page's origin, such as SSO buttons and crypto libraries, can be attacked by the host page and by neighbouring scripts, which browser policy alone cannot stop. The authors define Defensive JavaScript, a typed subset whose scripts keep their behaviour in a hostile page, and add a type inference tool, defensive crypto libraries and protocol verification.

Record

Researcher
Karthikeyan Bhargavan, Antoine Delignat-Lavaud and Sergio Maffeis

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Karthikeyan Bhargavan, Antoine Delignat-Lavaud and Sergio Maffeis, first published at the original source. Preserved copies are kept so the citation survives its host.