4 ms·
Let me know if you think it's all wrong :)
by albinowax_ 10y ago
Let me know if you think it's all wrong :)
- deleted 10y ago[deleted]
- gregwebs 10y agoIt would be great if you could talk in more specifics about attack scenarios against local storage. In particular one attack cited in favor of cookies is the scenario where your 3rd party CDN js hacked and some code is inserted into the JS to lift out the token from local storage.
- d1plo1d 10y agoSo that is similar to an XSS in that it gains you the ability to inject arbitrary JS in to the page. That scenario is covered in the article with as I understood it the TL;DR being that lifting tokens is less practical in practice then using the browser directly to send malicious requests. The result of either attack are also similar in that as soon as your injecting JS into the page you've gained access to the users session.
- vec 10y agoIf a third party can inject arbitrary JS onto your page then how you store your session token is far from your biggest problem.
- mark242 10y agoYes, this. If you are working with any sort of confidential data, be it personal information, or payment info, or whatever, a determined attacker with access to executing Javascript on your page is going to cause a world of problems, the least of which is gaining access to localStorage. A much more concise example is adding a simple eventlistener on keypress, and just logging that data to a third party. localStorage is ready for widespread use, imo, you just need to know what and when to use it; using localStorage as initial cached state on application startup is extremely useful.
- albinowax_ 10y agoIn the scenario you mention, you're scuppered regardless of whether sessions are stored. The best way to mitigate this particular problem is to use subresource integrity: https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres...