Collected research
Language-based Defenses Against Untrusted Browser Origins
Script components sharing a page's origin, such as SSO buttons and crypto libraries, can be attacked by the host page and by neighbouring scripts, which browser policy alone cannot stop. The authors define Defensive JavaScript, a typed subset whose scripts keep their behaviour in a hostile page, and add a type inference tool, defensive crypto libraries and protocol verification.
Record
- Researcher
- Karthikeyan Bhargavan, Antoine Delignat-Lavaud and Sergio Maffeis
- Published by
- usenix.org
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Karthikeyan Bhargavan, Antoine Delignat-Lavaud and Sergio Maffeis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .