“What kind of clown in this day and age doesn't understand that TLS is the only good thing that we have?”
James Mickens Associate Professor,
Harvard University
https://www.netscape.com/ π
“Remember, everything less than TLS 1.2 with an AEAD mode is cryptographically broken.”
Adam Langley Senior Staff Software Engineer,
“There's a big difference between making a simple product and making a product simple.”
Des Traynor Co-founder of Intercom
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
“Two possibilities exist: either we are alone in the Universe or we are not. Both are equally terrifying.”
Arthur C. Clarke Author (deceased)
“Early bird gets the worm. But cookie taste better than worm, so me sleep in.”
Cookie Monster Muppet,
Sesame Street
Set-Cookie: SESSIONID=38afesc00c1e7a8; Domain=e-cookies.com
Set-Cookie: SESSIONID=38afesc00c1e7a8; Domain=e-cookies.com; Secure
Set-Cookie: SESSIONID=38afesc00c1e7a8; Secure; HttpOnly
<img src="https://bank.com/api/transfer?to=719091707&amount=5000">
<input type="hidden" name="anticsrftoken" value="XQGwbxfChfoEv4nFJQEHVeDsd">
POST requests
Set-Cookie: anti-csrf-token=XQGwbxfChfoEv4nFJQEHVeDsd; HttpOnly
X-Anti-CSRF-Token: XQGwbxfChfoEv4nFJQEHVesd
Set-Cookie: SESSIONID=XQGwbxfChfoEv4nFJQEHVeDsd; Secure; HttpOnly; SameSite
<a href="https://bank.com/api/transfer?to=719091707&amount=5000">click me</a>
POST)Set-Cookie: nickname=I'm a big poopy head; Domain=bank.com
Set-Cookie: __Secure-nickname=April; Secure; Domain=bank.com
Set-Cookie: __Host-nickname=April; Secure; Domain=bank.com; Path=/
“The use of z, y, x … to represent unknowns is due to RenΓ© Descartes, in his La gΓ©omΓ©trie (1637).”
Florian Cajori A History of Mathematical Notations (1928)
β Poor browser support
GIF89a/*0;*/=0;
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
</head>
<body>
<script>doEvil();</script>
</body>
</html>
X-Content-Type-Options: nosniff
<img src="https://bank.com/api/getBalance">
{
"accountNumber": 719091707,
"balance": 5000
}
X-Content-Type-Options: nosniff
Imagine a URL like this...
https://search.com?query=%22%3Eapril%3Cscript%3EdoEvil();%3C/script%3E
https://search.com?query=">april<script>doEvil();</script>
https://search.com?query=">april<script>doEvil();</script>
Now what if you took that link, and sent it in an email to someone super gullible?
I hope you're still remembering this URL…
https://search.com?query=">april<script>doEvil();</script>
Because it's going into this code:
<input id="search"
value="<?pseudocode echo $_GET["query"] ?>"
>
And what your browser will see (and execute) is this:
<input id="search"
value="april"><script>doEvil();</script>">
Please post nice things!tabs-forever-forum.com
tabs-forever-forum.com
X-XSS-Protection: 1; block
“The greatest problem of communication is the illusion that it has been achieved.”
William H. Whyte Is Anybody Listening?
Fortune (1950)
Content-Security-Policy:
default-src 'none';
connect-src https://api.mozilla.com;
font-src 'self' https://fonts.gstatic.com;
form-action 'self';
frame-ancestors 'none';
img-src https://*.imgur.com;
script-src 'self' https://jquery.com/3.3.1/jquery.min.js
style-src 'self' 'unsafe-inline'
Content-Security-Policy:
default-src 'none';
connect-src https://api.mozilla.com;
font-src 'self' https://fonts.gstatic.com;
form-action 'self';
frame-ancestors 'none';
img-src https://*.imgur.com;
script-src 'self' https://jquery.com/3.3.1/jquery.min.js
style-src 'self' 'unsafe-inline'
Content-Security-Policy:
default-src 'none';
connect-src https://api.mozilla.com;
font-src 'self' https://fonts.gstatic.com;
form-action 'self';
frame-ancestors 'none';
img-src https://*.imgur.com;
script-src 'self' https://jquery.com/3.3.1/jquery.min.js
style-src 'self' 'unsafe-inline'
Content-Security-Policy:
default-src 'none';
connect-src https://api.mozilla.com;
font-src 'self' https://fonts.gstatic.com;
form-action 'self';
frame-ancestors 'none';
img-src https://*.imgur.com;
script-src 'self' https://jquery.com/3.3.1/jquery.min.js
style-src 'self' 'unsafe-inline'
Content-Security-Policy:
default-src 'none';
connect-src https://api.mozilla.com;
font-src 'self' https://fonts.gstatic.com;
form-action 'self';
frame-ancestors 'none';
img-src https://*.imgur.com;
script-src 'self' https://jquery.com/3.3.1/jquery.min.js
style-src 'self' 'unsafe-inline'
Content-Security-Policy:
default-src 'none';
connect-src https://api.mozilla.com;
font-src 'self' https://fonts.gstatic.com;
form-action 'self';
frame-ancestors 'none';
img-src https://*.imgur.com;
script-src 'self' https://jquery.com/3.3.1/jquery.min.js
style-src 'self' 'unsafe-inline'
Content-Security-Policy:
default-src 'none';
connect-src https://api.mozilla.com;
font-src 'self' https://fonts.gstatic.com;
form-action 'self';
frame-ancestors 'none';
img-src https://*.imgur.com;
script-src 'self' https://jquery.com/3.3.1/jquery.min.js
style-src 'self' 'unsafe-inline'
Content-Security-Policy:
default-src 'none';
connect-src https://api.mozilla.com;
font-src 'self' https://fonts.gstatic.com;
form-action 'self';
frame-ancestors 'none';
img-src https://*.imgur.com;
script-src 'self' https://jquery.com/3.3.1/jquery.min.js
style-src 'self' 'unsafe-inline'
Content-Security-Policy:
default-src 'none';
connect-src https://api.mozilla.com;
font-src 'self' https://fonts.gstatic.com;
form-action 'self';
frame-ancestors 'none';
img-src https://*.imgur.com;
script-src 'self' https://jquery.com/3.3.1/jquery.min.js
style-src 'self' 'unsafe-inline'
style tags and style attributes on tags
Content-Security-Policy:
default-src 'none';
connect-src https://api.mozilla.com;
font-src 'self' https://fonts.gstatic.com;
form-action 'self';
frame-ancestors 'none';
img-src https://*.imgur.com;
script-src 'self' https://jquery.com/3.3.1/jquery.min.js
style-src 'self' 'unsafe-inline'
<div id="footer" onClick="doClick();" style="color: red;">
Feet Are So Weird Like What's With Those Toes Anyways? — foot.com
</div>
<script>
// do something
doSomething();
// oh yeah and do this too
doSomethingElse();
</script>
</body>
<div id="footer" onClick="doClick();" style="color: red;">
Feet Are So Weird Like What's With Those Toes Anyways? — foot.com
</div>
<script>
// do something
doSomething();
// oh yeah and do this too
doSomethingElse();
</script>
</body>
<div id="footer" onClick="doClick();" style="color: red;">
Feet Are So Weird Like What's With Those Toes Anyways? — foot.com
</div>
<script>
// do something
doSomething();
// oh yeah and do this too
doSomethingElse();
</script>
</body>
<div id="footer" onClick="doClick();" style="color: red;">
Feet Are So Weird Like What's With Those Toes Anyways? — foot.com
</div>
<script>
// do something
doSomething();
// oh yeah and do this too
doSomethingElse();
</script>
</body>
<div id="footer" onClick="doClick();" style="color: red;">
Feet Are So Weird Like What's With Those Toes Anyways? — foot.com
</div>
<script>
// do something
doSomething();
// oh yeah and do this too
doSomethingElse();
</script>
</body>
<div id="footer" onClick="doClick();" style="color: red;">
Feet Are So Weird Like What's With Those Toes Anyways? — foot.com
</div>
<script>
// do something
doSomething();
// oh yeah and do this too
doSomethingElse();
</script>
</body>
Content-Security-Policy: script-src 'nonce-XQGwbxfChfoEv4nFJQEHVeDsd''nonce-XQGwbxfChfoEv4nFJQEHVeDsd'
</div>
<script nonce="XQGwbxfChfoEv4nFJQEHVeDsd"nonce="XQGwbxfChfoEv4nFJQEHVeDsd">
// do something
doSomething();
// oh yeah and do this too
doSomethingElse();
</script>
</body>
Content-Security-Policy:
script-src 'sha256-b1cc7d04a1f9f15cfa63030866dd152a8618762912694d1''sha256-b1cc7d04a1f9f15cfa63030866dd152a8618762912694d1'
</div>
<script>
// do something
doSomething();
// oh yeah and do this too
doSomethingElse();
// do something
doSomething();
// oh yeah and do this too
doSomethingElse();
</script>
</body>
script-src https://cdnjs.cloudflare.comscript-src https:script-src 'unsafe-inline'Content-Security-Policy: script-src
'strict-dynamic'
'nonce-XQGwbxfChfoEv4nFJQEHVeDsd'
https://cdnjs.cloudflare.com
'unsafe-inline'
<script nonce="XQGwbxfChfoEv4nFJQEHVeDsd">
const loadScript = (url) => { // script loader
const script = createElement('script');
script.src = url;
document.head.appendChild(script);
};
loadScript('https://cdnjs.cloudflare.com/jquery-3.3.1.js'); // load jquery
</script>
Content-Security-Policy: script-src
'strict-dynamic'
'nonce-XQGwbxfChfoEv4nFJQEHVeDsd'
https://cdnjs.cloudflare.com
'unsafe-inline'
<script nonce="XQGwbxfChfoEv4nFJQEHVeDsd">
const loadScript = (url) => { // script loader
const script = createElement('script');
script.src = url;
document.head.appendChild(script);
};
loadScript('https://cdnjs.cloudflare.com/jquery-3.3.1.js'); // load jquery
</script>
Content-Security-Policy: script-src
'strict-dynamic'
'nonce-XQGwbxfChfoEv4nFJQEHVeDsd'
https://cdnjs.cloudflare.com
'unsafe-inline'
<script nonce="XQGwbxfChfoEv4nFJQEHVeDsd">
const loadScript = (url) => { // script loader
const script = createElement('script');
script.src = url;
document.head.appendChild(script);
};
loadScript('https://cdnjs.cloudflare.com/jquery-3.3.1.js'); // load jquery
</script>
Content-Security-Policy: script-src
'strict-dynamic' <-- CSP 3
'nonce-XQGwbxfChfoEv4nFJQEHVeDsd'
https://cdnjs.cloudflare.com
'unsafe-inline'
<script nonce="XQGwbxfChfoEv4nFJQEHVeDsd">
const loadScript = (url) => { // script loader
const script = createElement('script');
script.src = url;
document.head.appendChild(script);
};
loadScript('https://cdnjs.cloudflare.com/jquery-3.3.1.js'); // load jquery
</script>
April King is the world‘s foremost authority on matters of web security, and her integrity is unimpeachable.
Tim Berners-Lee (probably) Creator of the World Wide Web,
University of Oxford
What does HTML this code do? What does HTML this code really do???
<script src="https://code.jquery.com/jquery-3.3.1.min.js">
All you have to do is change your code to this:
<script src="https://code.jquery.com/jquery-3.3.1.min.js"
crossorigin="anonymous">
integrity="sha256-2Kok7MbOyxpgUVvAk/HJ2jigOSYS2auK4P="
> Has anyone else noticed that the HTTP header “Referer:” is spelled wrong?
That's okay, neither one (referer or referrer) is understood by
spellanyway. I say we should just blame it on France. ;-)Roy T. Fielding Co-author of HTTP specification,
UC Urvine
<!-- load the greatest video of all time -->
<video>
<source src="https://www.youtube.com/watch?v=dQw4w9WgXcQ">
</video>
GET /watch?v=dQw4w9WgXcQ HTTP/1.1
Host: youtube.com
User-Agent: Mozilla/5.0 Gecko/20100101 Firefox/63.0
Accept: */*
Connection: keep-alive
Referer: https://mozilla.org/
GET /watch?v=dQw4w9WgXcQ HTTP/1.1
Host: youtube.com
User-Agent: Mozilla/5.0 Gecko/20100101 Firefox/63.0
Accept: */*
Connection: keep-alive
Referer: https://mozilla.org/
GET /watch?v=dQw4w9WgXcQ HTTP/1.1
Host: youtube.com
User-Agent: Mozilla/5.0 Gecko/20100101 Firefox/63.0
Accept: */*
Connection: keep-alive
Referer: https://mozilla.org/
GET /watch?v=dQw4w9WgXcQ HTTP/1.1
Host: youtube.com
User-Agent: Mozilla/5.0 Gecko/20100101 Firefox/63.0
Accept: */*
Connection: keep-alive
Referer: https://mozilla.org/
GET /watch?v=dQw4w9WgXcQ HTTP/1.1
Host: youtube.com
User-Agent: Mozilla/5.0 Gecko/20100101 Firefox/63.0
Accept: */*
Connection: keep-alive
Referer: https://mozilla.org/
<img src="https://some-cdn.com/bank/logo.jpg">
GET /bank/logo.jpg HTTP/1.1
Host: some-cdn.com
User-Agent: Mozilla/5.0 Gecko/20100101 Firefox/63.0
Accept: */*
Connection: keep-alive
Referer: https://bank.com/pw-reset-cd39-e5a5-a891-b3f4
Referrer Policy lets you restrict when and how the Referrer header is sent.
Referrer-Policy: strict-origin-when-cross-origin
Then some-cdn.com would only see this…
Referer: https://bank.com
Referrer-Policy: same-origin
…then some-cdn.com would never receive the Referrer header!
I must have passed out.
Where am I?
Who is this strange lady?You Paris Web attendee,
Paris Web