Web Hack List

Collected research

Language-based Defenses Against Untrusted Browser Origins

Script components sharing a page's origin, such as SSO buttons and crypto libraries, can be attacked by the host page and by neighbouring scripts, which browser policy alone cannot stop. The authors define Defensive JavaScript, a typed subset whose scripts keep their behaviour in a hostile page, and add a type inference tool, defensive crypto libraries and protocol verification.

Record

Researcher
Karthikeyan Bhargavan, Antoine Delignat-Lavaud and Sergio Maffeis
Published by
usenix.org
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Karthikeyan Bhargavan, Antoine Delignat-Lavaud and Sergio Maffeis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .