3 ms·
> Not that any of this will ever be deployed[2], because they're two of the most invasive defence measures [...] SRI is going to be a tough sell. CSP, not so m
by phlo 11y ago
> Not that any of this will ever be deployed[2], because they're two of the most invasive defence measures [...]
SRI is going to be a tough sell. CSP, not so much.
Case in point: within two years, HSTS use by Swiss Banks has gone from 0% to 40%. I managed to get the first deployment up and running, and at this point we made it into the preload lists. If just one company gets any of this stuff up and running (and whomever did it keeps pestering their colleagues at some others about it), adoption is possible.
Right now I'm working on getting some traction with HPKP and CSP. HPKP is going to be challenging as doesn't offer protection against user-installed (or malware-installed) root certificates, but seeing how the cost of adoption is low, it shouldn't be impossible.
CSP should be easier. Being the responsible bank we are, we aren't dropping any javascript files from CDNs into our pages. Anything running in our domain originates from there, so it's basically down to starting with -Report-Only, unsafe-eval and unsafe-inline options and gradually moving towards *-src 'self'. And it provides valuable protection against all sorts of Adware and Malware.
Ping me in a year. I'm confident we'll get there by then.
- nailer 11y ago> HSTS use by Swiss Banks has gone from 0% to 40%. That's awesome. Do you have a reference? Not doubting you, just want to read more.
- phlo 11y agoSorry, I don't have a public reference. The first number came from my (unpublished) 2013 bachelor's thesis, where I surveyed the 20 biggest banks (by balance sheet) in each of CH, DE, AT, IT and FR. HSTS was very new back then, so the 0% was no big surprise. The full thesis is in German. I can send you the PDF if you're interested. For the second number, I had a look at 15 banks represented at Vontobel, Credit Suisse, J. Safra Sarasin, PostFinance, Raiffeisen, Swissquote, UBS, Valiant and the State Banks from Basel, Geneva, Grisons, Schaffhausen, Thurgovia, Zug and Zurich. Of these 15 banks, six were using HSTS: CS, PostFinance, Raiffeisen as well as Basel, Thurgovia, Zug and Zurich. Switzerland has over 200 banks in total, but many of these are small private shops, only a couple dozen actually offer e-banking. The majority of people is banking with one of the top 5 (PF/CS/Raiffeisen already are, and I'm hoping for UBS and Valiant to adopt HSTS soon-ish). The 15 I had a look at in December 2015 are responsible for the vast majority (90+%) of online banking done in Switzerland.