History of Web Security

& the Mozilla Observatory
2018.10.04
April King
Staff Security Engineer
Mozilla
Agenda
  1. Teaching you everything
    • I'm a liar
    • Start in 1994
    • End in a half-hour, after everyone has fled the room
  2. Test your knowledge
The Real
Agenda
  1. Connection security (SSL/TLS)
    • … and how we made it “easy”
  2. Same-origin policy
  3. Cookies & cross-site request forgeries (CSRF)
  4. Framing & clickjacking
  5. Abusing content sniffing
  6. Cross-site scripting & Content Security Policy
  7. Nobody reads these things
  8. You can't trust other people
  9. But it's going to be okay anyways

“What kind of clown in this day and age doesn't understand that TLS is the only good thing that we have?”

James Mickens Associate Professor,
Harvard University

Secure Sockets Layer 2.0

  • In 1995, Netscape released Netscape Navigator 1.1
  • First browser with support for secure HTTP
  • https://www.netscape.com/ πŸ”’

Secure Sockets Layer 3.0 &

Private Communications Technology 1.0

  • Fixed a lot of security shortfalls in SSL 2.0
  • Microsoft’s PCT was only supported by Internet Explorer

Transport Layer Security 1.0

  • Fixed some bugs, but is the same thing as SSL 3.0
  • ProtocolVersion is { 3 , 1 }
  • Netscape and Microsoft IETF standardization
  • Name changed to Transport Layer Security as part of negotiations

Transport Layer Security 1.2

  • Further cleanup and bug fixes
  • Added a lot of flexibility via TLS Extensions
  • Added support for Advanced Encryption Standard (AES) cipher and AEADs

Authenticated Encryption with Associated Data (AEAD)

  • Combining a cipher, block mode, and message authentication code (MACs) was really hard

  • AEADs combine all three into a single unit
  • Most common are AES-GCM (AES in Galois/Counter mode) and ChaCha20-Poly1305

Transport Layer Security

  • Overall, individual differences from SSL 3.0 to TLS 1.2 are minor
  • Fix a pile of bugs and considerably clean things up
  • Add a lot of flexibility to the protocol

“Remember, everything less than TLS 1.2 with an AEAD mode is cryptographically broken.”

Adam Langley Senior Staff Software Engineer,
Google

Transport Layer Security 1.3

  • Further removed a lot of cruft (MD5, RC4, SSL fallbacks, weak elliptic curves)
  • Requires AEADs and more secure forms of handshakes
  • Much faster handshakes, with fewer round trips

Transport Layer Security 1.2 handshake

Transport Layer Security 1.3 handshake

Transport Layer Security 1.3 handshake resumption

Transport Layer Security 1.3

  • Available in Firefox 63, Chrome 70

“There's a big difference between making a simple product and making a product simple.”

Des Traynor Co-founder of Intercom

Server Name Indication (SNI)

  • Early versions of SSL and TLS only supported one certificate per IP address
  • Didn't match up well with the realities of web hosting
  • Let clients tell servers which host they wanted to connect to
  • Downsides of letting eavesdroppers know which domain you're connecting to

HTTP Strict Transport Security (HSTS)

  • Tells your browser that you want to go to http://badssl.com/

HTTP Strict Transport Security (HSTS)

HTTP Strict Transport Security (HSTS)

HTTP Strict Transport Security (HSTS)

HTTP Strict Transport Security (HSTS)

HTTP Strict Transport Security (HSTS)

HTTP Strict Transport Security (HSTS)

HTTP Strict Transport Security (HSTS)

HTTP Strict Transport Security (HSTS)

HTTP Strict Transport Security (HSTS)

HTTP Strict Transport Security (HSTS)

HTTP Strict Transport Security (HSTS)

  • Lets servers tell browsers to always visit site over HTTPS for a period
  • Doesn't solve first use problem

HSTS Preloading

  • What if browsers came bundled with a giant list of sites that were only HTTPS?
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
  • Applies to all subdomains
  • Supported by every browser
  • Takes a very long time to get off
  • GIANT LIST OF SITES

HTTP Public Key Pinning (HPKP)

  • Certificate authorities sometimes issue certificates that they shouldn't
  • A way to pin sites to specific root certificate, intermediate certificate, or public keys
    • Maybe 100 sites will use this
    • It's super complicated and easy to screw up

Certificate Transparency

  • Append-only lists of certificates issued by certificate authorities
    • Check for issued certificates that you didn't request
    • Check to see if certificates encountered in the wild aren't in the logs
  • Required for some types of certificates already, eventually all certificates

Digital Certificates

  • Digital certificates are like a driver's license for a website
  • They are required to setup secure websites
  • The entities selling them want to make money
  • And so digital certificates were expensive and complicated

  • Free
  • Automated
  • Transparent
  • Open Source

  • Here’s where I show off a sweet chart about HTTPS usage
    (note to self: rewrite to something more professional before presentation)

“Two possibilities exist: either we are alone in the Universe or we are not. Both are equally terrifying.”

Arthur C. Clarke Author (deceased)

Same-origin Policy

  • Sites can execute code from any origin, but they can only directly read content from the same-origin.
  • Running JavaScript, rendering images and fonts, loading a frame
  • Reading the content of what they loaded
https:// www.mozilla.org :443
  • Read the content of the same-origin, but nowhere else

“Early bird gets the worm. But cookie taste better than worm, so me sleep in.”

Cookie Monster Muppet,
Sesame Street
?

Secure Cookies

Set-Cookie: SESSIONID=38afesc00c1e7a8; Domain=e-cookies.com
  • Browser sends the SESSIONID cookie every time you visit e-cookies.com, even over HTTP
  • This is very bad
Set-Cookie: SESSIONID=38afesc00c1e7a8; Domain=e-cookies.com; Secure
  • The Secure flag tells browsers to not do the bad thing
  • Set on every cookie, as long as you support HTTPS (which you should)
  • HttpOnly Cookies

    • Browser makers understood that JavaScript came from all sorts of unscrupulous places
    • HttpOnly flag prevents JavaScript code from accessing sensitive cookies
    Set-Cookie: SESSIONID=38afesc00c1e7a8; Secure; HttpOnly
    • You should use it
    • Not nearly as important as preventing untrusted JavaScript from running

    SameSite Cookies

    • Super easy
    • Save a ton of time
    • You should use them
    • But how????? And why????

    Cross-site request forgeries (CSRF)

    • Here is what I know
    • There are three things people want in life

    Cross-site request forgeries (CSRF)

    • To do this, browsers must support <img> and <video> tags

    <img src="https://bank.com/api/transfer?to=719091707&amount=5000">
    • πŸ€” πŸ€” πŸ€” πŸ€” πŸ€” πŸ€” πŸ€” πŸ€” πŸ€” πŸ€” πŸ€” πŸ€” πŸ€”
    • Browsers: πŸ‘
    • How do you tell an authentic request from a forgery?
      • They both have session cookies

    Cross-site request forgeries (CSRF)

    • Synchronizer tokens

    <input type="hidden" name="anticsrftoken" value="XQGwbxfChfoEv4nFJQEHVeDsd">

      • Protected by same-origin policy
      • They need to be unique and unpredictable, only work with POST requests
      • Can cause problems with multiple tabs and erratic user flows

    • Cookie-to-header tokens

    Set-Cookie: anti-csrf-token=XQGwbxfChfoEv4nFJQEHVeDsd; HttpOnly
    X-Anti-CSRF-Token: XQGwbxfChfoEv4nFJQEHVesd

      • Also protected by same-origin policy
      • Must be unpredictable, stable across entire session
      • Only works if JavaScript is enabled

    SameSite Cookies

    Set-Cookie: SESSIONID=XQGwbxfChfoEv4nFJQEHVeDsd; Secure; HttpOnly; SameSite

    • SameSite tells browsers to only ever send the cookie when you're on a site
    • SameSite=Strict (default) won't send the cookies even on navigation
    <a href="https://bank.com/api/transfer?to=719091707&amount=5000">click me</a>
    • SameSite=Lax will let browsers send cookies on top-level navigations
      • Protects unsafe methods (like POST)

    • Only supported by modern web browsers, so use in conjunction with other anti-CSRF methods for now

    Cookie Prefixes

    • Quite a number of attacks have come from leveraging an insecure site to attack a secure one
    • Sites can set cookies on any parent domain
    http://poorlycodedwebsite
    .pleasedontfindthis
    .mybosswillfireme
    .test
    .bank.com
    Set-Cookie: nickname=I'm a big poopy head; Domain=bank.com

    Cookie Prefixes

    Set-Cookie: __Secure-nickname=April; Secure; Domain=bank.com
    • Prevent cookie from being set or overwritten by HTTP origins

    Set-Cookie: __Host-nickname=April; Secure; Domain=bank.com; Path=/
    • Prevent cookie from being set or overwritten by either HTTP origins or other systems.

    “The use of z, y, x … to represent unknowns is due to RenΓ© Descartes, in his La gΓ©omΓ©trie (1637).”

    Florian Cajori A History of Mathematical Notations (1928)

    X marks the spot

    • Internet Explorer 8 introduced a trio of security headers

    X-Frame-Options

    • Tells browsers whether or not your site could be framed or iframed
      • X-Frame-Options: DENY
      • X-Frame-Options: SAMEORIGIN
      • X-Frame-Options: ALLOW-FROM https://mozilla.org/†

    † Poor browser support

    Clickjacking

    Clickjacking

    X-Frame-Options

    • Now deprecated by other, more flexible standards
    • Can still use if you have old clients and mostly need DENY

    X-Content-Type-Options

    • Protects against MIME type confusion attacks

    
    GIF89a/*0;*/=0;
    <!DOCTYPE html>
    <html lang="en">
      <head>
        <meta charset="utf-8">
      </head>
      <body>
        <script>doEvil();</script>
      </body>
    </html>
              
    X-Content-Type-Options: nosniff
    • Tells browsers to disable content sniffing

    X-Content-Type-Options

    • Helps stop attacks like Spectre and Meltdown
    <img src="https://bank.com/api/getBalance">
    
              {
                "accountNumber": 719091707,
                "balance": 5000
              }

    X-Content-Type-Options: nosniff
    • Basically no downside, help enforce the proper behavior

    X-XSS-Protection

    Cross-site scripting (XSS)

    Imagine a URL like this...

    https://search.com?query=%22%3Eapril%3Cscript%3EdoEvil();%3C/script%3E
    https://search.com?query=">april<script>doEvil();</script>
    https://search.com?query=">april<script>doEvil();</script>

    Now what if you took that link, and sent it in an email to someone super gullible?

    Cross-site scripting (XSS) (Reflected)

    I hope you're still remembering this URL…

    https://search.com?query=">april<script>doEvil();</script>

    Because it's going into this code:

    
                <input id="search"
                       value="<?pseudocode echo $_GET["query"] ?>"
                >
              

    And what your browser will see (and execute) is this:

    
    <input id="search"
           value="april"><script>doEvil();</script>">
              

    Cross-site scripting (XSS) (Stored)

    Please post nice things!tabs-forever-forum.com

    Cross-site scripting (XSS) (Stored)

    tabs-forever-forum.com

    X-XSS-Protection

    • Cross-site scripting attacks are an extremely common attack
    • Have potential to be quite damaging

    X-XSS-Protection: 1; block

    • X-XSS-Protection detects reflected cross-site scripting attacks
    • Behavior is not really defined anywhere, uneven browser support
    • Don't expect miracles from it

    “The greatest problem of communication is the illusion that it has been achieved.”

    William H. Whyte Is Anybody Listening?
    Fortune (1950)

    The Fundamental Problem

    Content Security Policy

    • Permission system for your web site
    • Tells your browser things like:
      • Where can I load content from (scripts, images, etc.)
      • Who can I make XMLHttpRequest (XHR) connections to
      • Who can I be framed by, and who can I frame?
      • Can script that's been mixed with content be executed?

    Content Security Policy

    
                Content-Security-Policy:
                  default-src 'none';
                  connect-src https://api.mozilla.com;
                  font-src 'self' https://fonts.gstatic.com;
                  form-action 'self';
                  frame-ancestors 'none';
                  img-src https://*.imgur.com;
                  script-src 'self' https://jquery.com/3.3.1/jquery.min.js
                  style-src 'self' 'unsafe-inline'
              
    
                Content-Security-Policy:
                  default-src 'none';
                  connect-src https://api.mozilla.com;
                  font-src 'self' https://fonts.gstatic.com;
                  form-action 'self';
                  frame-ancestors 'none';
                  img-src https://*.imgur.com;
                  script-src 'self' https://jquery.com/3.3.1/jquery.min.js
                  style-src 'self' 'unsafe-inline'
              
    • Any source without a -src directive (e.g. audio and video) is denied access
    
                Content-Security-Policy:
                  default-src 'none';
                  connect-src https://api.mozilla.com;
                  font-src 'self' https://fonts.gstatic.com;
                  form-action 'self';
                  frame-ancestors 'none';
                  img-src https://*.imgur.com;
                  script-src 'self' https://jquery.com/3.3.1/jquery.min.js
                  style-src 'self' 'unsafe-inline'
              
    • Can make XMLHttpRequests (XHR) to api.mozilla.com
    
                Content-Security-Policy:
                  default-src 'none';
                  connect-src https://api.mozilla.com;
                  font-src 'self' https://fonts.gstatic.com;
                  form-action 'self';
                  frame-ancestors 'none';
                  img-src https://*.imgur.com;
                  script-src 'self' https://jquery.com/3.3.1/jquery.min.js
                  style-src 'self' 'unsafe-inline'
              
    • Can load fonts from the same origin and Google Fonts
    
                Content-Security-Policy:
                  default-src 'none';
                  connect-src https://api.mozilla.com;
                  font-src 'self' https://fonts.gstatic.com;
                  form-action 'self';
                  frame-ancestors 'none';
                  img-src https://*.imgur.com;
                  script-src 'self' https://jquery.com/3.3.1/jquery.min.js
                  style-src 'self' 'unsafe-inline'
              
    • Forms can only be submitted to the same origin
    
                Content-Security-Policy:
                  default-src 'none';
                  connect-src https://api.mozilla.com;
                  font-src 'self' https://fonts.gstatic.com;
                  form-action 'self';
                  frame-ancestors 'none';
                  img-src https://*.imgur.com;
                  script-src 'self' https://jquery.com/3.3.1/jquery.min.js
                  style-src 'self' 'unsafe-inline'
              
    • Nothing can frame this site, not even itself.
    • Same as X-Frame-Options: DENY
    
                Content-Security-Policy:
                  default-src 'none';
                  connect-src https://api.mozilla.com;
                  font-src 'self' https://fonts.gstatic.com;
                  form-action 'self';
                  frame-ancestors 'none';
                  img-src https://*.imgur.com;
                  script-src 'self' https://jquery.com/3.3.1/jquery.min.js
                  style-src 'self' 'unsafe-inline'
              
    • Can load images from any imgur.com subdomain
    
                Content-Security-Policy:
                  default-src 'none';
                  connect-src https://api.mozilla.com;
                  font-src 'self' https://fonts.gstatic.com;
                  form-action 'self';
                  frame-ancestors 'none';
                  img-src https://*.imgur.com;
                  script-src 'self' https://jquery.com/3.3.1/jquery.min.js
                  style-src 'self' 'unsafe-inline'
              
    • Can load scripts from same origin and one specific jQuery script
    
                Content-Security-Policy:
                  default-src 'none';
                  connect-src https://api.mozilla.com;
                  font-src 'self' https://fonts.gstatic.com;
                  form-action 'self';
                  frame-ancestors 'none';
                  img-src https://*.imgur.com;
                  script-src 'self' https://jquery.com/3.3.1/jquery.min.js
                  style-src 'self' 'unsafe-inline'
              
    • Can load stylesheets from same origin and allows (unsafe) style tags and style attributes on tags
    
                Content-Security-Policy:
                  default-src 'none';
                  connect-src https://api.mozilla.com;
                  font-src 'self' https://fonts.gstatic.com;
                  form-action 'self';
                  frame-ancestors 'none';
                  img-src https://*.imgur.com;
                  script-src 'self' https://jquery.com/3.3.1/jquery.min.js
                  style-src 'self' 'unsafe-inline'
              
    • Can load stylesheets from same origin and allows (unsafe) style attributes on tags

    Mozilla Laboratory Add-on

    • Free add-on for Firefox that can generate a Content Security Policy
    • Click around on things while it watches

    Content Security Policy (is not easy)

    • Strongly encourages separation of content, presentation, and code

    
                <div id="footer" onClick="doClick();" style="color: red;">
                  Feet Are So Weird Like What's With Those Toes Anyways? — foot.com
                </div>
                <script>
                  // do something
                  doSomething();
    
                  // oh yeah and do this too
                  doSomethingElse();
                </script>
              </body>
              
    
                <div id="footer" onClick="doClick();" style="color: red;">
                  Feet Are So Weird Like What's With Those Toes Anyways? — foot.com
                </div>
                <script>
                  // do something
                  doSomething();
    
                  // oh yeah and do this too
                  doSomethingElse();
                </script>
              </body>
              
    
                <div id="footer" onClick="doClick();" style="color: red;">
                  Feet Are So Weird Like What's With Those Toes Anyways? — foot.com
                </div>
                <script>
                  // do something
                  doSomething();
    
                  // oh yeah and do this too
                  doSomethingElse();
                </script>
              </body>
              
    
                <div id="footer" onClick="doClick();" style="color: red;">
                  Feet Are So Weird Like What's With Those Toes Anyways? — foot.com
                </div>
                <script>
                  // do something
                  doSomething();
    
                  // oh yeah and do this too
                  doSomethingElse();
                </script>
              </body>
              
    
                <div id="footer" onClick="doClick();" style="color: red;">
                  Feet Are So Weird Like What's With Those Toes Anyways? — foot.com
                </div>
                <script>
                  // do something
                  doSomething();
    
                  // oh yeah and do this too
                  doSomethingElse();
                </script>
              </body>
              
    
                <div id="footer" onClick="doClick();" style="color: red;">
                  Feet Are So Weird Like What's With Those Toes Anyways? — foot.com
                </div>
                <script>
                  // do something
                  doSomething();
    
                  // oh yeah and do this too
                  doSomethingElse();
                </script>
              </body>
              
    • By default, CSP will block the execution of inline styles
    • By default, CSP will block the execution of inline script
    • You can disable this with the 'unsafe-inline' directive
    • But this just opens you back up to injection attacks

    Content Security Policy (inline stuff)

    Content-Security-Policy: script-src 'nonce-XQGwbxfChfoEv4nFJQEHVeDsd''nonce-XQGwbxfChfoEv4nFJQEHVeDsd'
    
                  </div>
                  <script nonce="XQGwbxfChfoEv4nFJQEHVeDsd"nonce="XQGwbxfChfoEv4nFJQEHVeDsd">
                    // do something
                    doSomething();
    
                    // oh yeah and do this too
                    doSomethingElse();
                  </script>
                </body>
                

    • You set an unpredictible nonce in your Content Security Policy, and tag all trusted code with it

    Content Security Policy (more inline stuff)

    Content-Security-Policy:
      script-src 'sha256-b1cc7d04a1f9f15cfa63030866dd152a8618762912694d1''sha256-b1cc7d04a1f9f15cfa63030866dd152a8618762912694d1'
    
                  </div>
                  <script> 
                    // do something
                    doSomething();
    
                    // oh yeah and do this too
                    doSomethingElse();
                   
                    // do something
                    doSomething();
    
                    // oh yeah and do this too
                    doSomethingElse();
                  </script>
                </body>
                

    • You can generate cryptographic hashes of your inline script

    Content Security Policy 3

    • Complex websites had difficulty tracking what scripts they were using
    • They were doing bad things like
      • script-src https://cdnjs.cloudflare.com
      • script-src https:
      • script-src 'unsafe-inline'
    • Added support for script-src 'strict-dynamic'

    Content Security Policy

    Content Security Policy

    Content Security Policy

    Content Security Policy 3 (very strict much discipline)

    Content-Security-Policy: script-src 
                               'strict-dynamic'
                               'nonce-XQGwbxfChfoEv4nFJQEHVeDsd'
                               https://cdnjs.cloudflare.com
                               'unsafe-inline'
    
                    <script nonce="XQGwbxfChfoEv4nFJQEHVeDsd">
                      const loadScript = (url) => {  // script loader
                        const script = createElement('script');
                        script.src = url;
                        document.head.appendChild(script);
                      };
    
                      loadScript('https://cdnjs.cloudflare.com/jquery-3.3.1.js'); // load jquery
                    </script>
                    
    Content-Security-Policy: script-src 
                               'strict-dynamic'
                               'nonce-XQGwbxfChfoEv4nFJQEHVeDsd'
                               https://cdnjs.cloudflare.com
                               'unsafe-inline'
    
                    <script nonce="XQGwbxfChfoEv4nFJQEHVeDsd">
                      const loadScript = (url) => {  // script loader
                        const script = createElement('script');
                        script.src = url;
                        document.head.appendChild(script);
                      };
    
                      loadScript('https://cdnjs.cloudflare.com/jquery-3.3.1.js'); // load jquery
                    </script>
                    
    Content-Security-Policy: script-src 
                               'strict-dynamic'
                               'nonce-XQGwbxfChfoEv4nFJQEHVeDsd'
                               https://cdnjs.cloudflare.com
                               'unsafe-inline'
    
                    <script nonce="XQGwbxfChfoEv4nFJQEHVeDsd">
                      const loadScript = (url) => {  // script loader
                        const script = createElement('script');
                        script.src = url;
                        document.head.appendChild(script);
                      };
    
                      loadScript('https://cdnjs.cloudflare.com/jquery-3.3.1.js'); // load jquery
                    </script>
                    
    Content-Security-Policy: script-src 
                               'strict-dynamic' <-- CSP 3
                               'nonce-XQGwbxfChfoEv4nFJQEHVeDsd'
                               https://cdnjs.cloudflare.com
                               'unsafe-inline'
    
                    <script nonce="XQGwbxfChfoEv4nFJQEHVeDsd">
                      const loadScript = (url) => {  // script loader
                        const script = createElement('script');
                        script.src = url;
                        document.head.appendChild(script);
                      };
    
                      loadScript('https://cdnjs.cloudflare.com/jquery-3.3.1.js'); // load jquery
                    </script>
                  
    • No need for broad sources or huge and complicated lists
    • Anything with the nonce can load, and its trust is inherited
    80%

    April King is the world‘s foremost authority on matters of web security, and her integrity is unimpeachable.

    Tim Berners-Lee (probably) Creator of the World Wide Web,
    University of Oxford

    Subresource Integrity

    What does HTML this code do? What does HTML this code really do???

    <script src="https://code.jquery.com/jquery-3.3.1.min.js">
    • Make malicious XHR (XMLHttpRequests) requests
    • Read all non-HttpOnly cookies
    • Record every keystroke and form entry
    • Abuse permissions to the camera, geolocation, etc.
    • It could even deface your website! 😀
    πŸŽ‚ 🍽 🀯

    Subresource Integrity

    All you have to do is change your code to this:

    <script src="https://code.jquery.com/jquery-3.3.1.min.js"
            crossorigin="anonymous">
            integrity="sha256-2Kok7MbOyxpgUVvAk/HJ2jigOSYS2auK4P="
    • Browser will check to see if the JavaScript matches cryptographic hash prior to execution
    • If somebody breaks in and changes the file, it won’t execute
    • Good to have local fallback if loading fails

    > Has anyone else noticed that the HTTP header “Referer:” is spelled wrong?

    That's okay, neither one (referer or referrer) is understood by spell anyway. I say we should just blame it on France.  ;-)

    Roy T. Fielding Co-author of HTTP specification,
    UC Urvine

    Referrer Policy

    • Let's say you're on mozilla.org, and you see a piece of code like this…
    
    <!-- load the greatest video of all time -->
    <video>
      <source src="https://www.youtube.com/watch?v=dQw4w9WgXcQ">
    </video>
              
    • What kind of HTTP request does it send?
    
                GET /watch?v=dQw4w9WgXcQ HTTP/1.1
                Host: youtube.com
                User-Agent: Mozilla/5.0 Gecko/20100101 Firefox/63.0
                Accept: */*
                Connection: keep-alive
                Referer: https://mozilla.org/
              
    
                GET /watch?v=dQw4w9WgXcQ HTTP/1.1
                Host: youtube.com
                User-Agent: Mozilla/5.0 Gecko/20100101 Firefox/63.0
                Accept: */*
                Connection: keep-alive
                Referer: https://mozilla.org/
              
    
                GET /watch?v=dQw4w9WgXcQ HTTP/1.1
                Host: youtube.com
                User-Agent: Mozilla/5.0 Gecko/20100101 Firefox/63.0
                Accept: */*
                Connection: keep-alive
                Referer: https://mozilla.org/
              
    
                GET /watch?v=dQw4w9WgXcQ HTTP/1.1
                Host: youtube.com
                User-Agent: Mozilla/5.0 Gecko/20100101 Firefox/63.0
                Accept: */*
                Connection: keep-alive
                Referer: https://mozilla.org/
              
    
                GET /watch?v=dQw4w9WgXcQ HTTP/1.1
                Host: youtube.com
                User-Agent: Mozilla/5.0 Gecko/20100101 Firefox/63.0
                Accept: */*
                Connection: keep-alive
                
    Referer: https://mozilla.org/

    Referrer Policy

    • Even worse, if you're at an unlisted page such as
      bank.com/pw-reset-cd39-e5a5-a891-b3f4,
      you might have something like this:
    
              <img src="https://some-cdn.com/bank/logo.jpg">
              
    
                GET /bank/logo.jpg HTTP/1.1
                Host: some-cdn.com
                User-Agent: Mozilla/5.0 Gecko/20100101 Firefox/63.0
                Accept: */*
                Connection: keep-alive
                Referer: https://bank.com/pw-reset-cd39-e5a5-a891-b3f4
              

    Referrer Policy

    Referrer Policy lets you restrict when and how the Referrer header is sent.

    • If bank.com instead sent something like this…
    
                 Referrer-Policy: strict-origin-when-cross-origin
                

    Then some-cdn.com would only see this…

    
                 Referer: https://bank.com
                
    • Or if it sent this…
    
                 Referrer-Policy: same-origin
                

    …then some-cdn.com would never receive the Referrer header!

    Referrer Policy

    • Considerable control over the Referrer header
    • Huge win for user privacy
    • Helps prevent accidental information disclosures
    • Still lets you collect full referrer data for your own domains

    I must have passed out.
    Where am I?
    Who is this strange lady?

    You Paris Web attendee,
    Paris Web

    SSL Labs (Qualys)

    • Configuring TLS cipher suites and protocols was really hard
    • You had no feedback if you were doing it right (or wrong)
    • Gave you a strict public letter grade

    Mozilla Server Side TLS Guidelines

    • Most frequently referenced TLS configurations
    • Made it easy to get that A+ grade
    • Configuration tool to generate easy copy-and-paste configurations

    Mozilla Observatory

    • As SSL Labs is for TLS, Mozilla Observatory is for front-end web security
    • 100% free and open-source
    • 8.5M scans across 2.5M domains

    Mozilla Observatory

    • Strict grading system – expect to fail the first time
    • Clear advice on what to do next, with links to documentation

    Mozilla Observatory (Tests)

    Mozilla Observatory (CSP)

    Mozilla Observatory (TLS)

    • If you follow the Mozilla TLS guidelines, it can test compliance

    Mozilla Observatory (the other cool stuff)

    • Command-line clients, Python libraries
    • Free public API, preconfigured system images for internal use
    • Integration with 3rd parties, such as SSL Labs
    • Please try it out at: observatory.mozilla.org

    April King

    History of Web Security
    & the Mozilla Observatory
    Feedback
    april@mozilla.com
    irc.mozilla.org #infosec
    github.com/april/websec-presentation
    ?