6 ms·
Everytime I read about such constructs, it makes me realize, as a regular developer, how complex web application security is and how difficult it is to think ab
by winteriscoming 9y ago
Everytime I read about such constructs, it makes me realize, as a regular developer, how complex web application security is and how difficult it is to think about and cover your application against each and every such potential problem.
- hdhzy 9y agoNote that these protections are only needed because Google supports every imaginable browser version even outdated ones. You most certainly do not need to do the same. Array and object globals cannot be overridden now (since 2007) for literals [0] and for ambient authority problem with CORS just check the Origin header. [0]: https://johnresig.com/blog/re-securing-json/ https://johnresig.com/blog/re-securing-json/
- emmelaich 9y agoThat would a good note to add to that StackOverflow question.
- fixermark 9y ago> You most certainly do not need to do the same. ... except that those browsers are still out there, so it depends heavily on how much damage someone can do by abusing the data your server can emit whether you need to do the same.
- deleted 9y ago[deleted]
- sagethesagesage 9y agoIt's more that people who use those browsers are being protected. It's not that those browsers can poke security holes in the site, they're just vulnerable to losing their own data.
- amenghra 9y agoIf you are browsing the web with a 10 year old browser you are opening yourself up to a ton of security bugs. Whether json responses contain a while loop or not isn't going to make a difference. The reason Google and Facebook keep this kind of stuff around is because it's there and doesn't hurt to keep it. There's a slight chance it will provide some protection if a similar attack vector is discovered.
- Roodgorf 9y agoBut aren't you saying this is an already existing attack vector then?? Why try to find a similar one if you knew you could just get an older browser version and use this one? Is that not a good enough reason to be prepared for it?
- hcs 9y agoAs sagethesagesage said [1], you're protecting the user from having their browser pass the user's data from your site to a malicious site. The attacker shouldn't be able to make the user run an old, vulnerable browser. [1] https://news.ycombinator.com/item?id=14282532 https://news.ycombinator.com/item?id=14282532
- winterlight 9y agoModern web development is already hard by itself, specially when it comes to security. A saner runtime language is needed to replace the sub par standard that is javascript. One with a robust type-system and coherent semantics. It won't fix every problem, but a least it would prevent abuses such as the one in question.
- vesinisa 9y agoWASM (WebAssembly) is about developing a very simple cross-browser bytecode that allows implementing any runtime on top of it. The first versions are already rolling out in latest major browser versions, but at this stage you don't yet get DOM access from WASM. After the initial phase when DOM access is implemented, it's the beginning of end for JavaScript. Future browsers might well implement JS as a pre-shipped runtime targeting the internal WASM core.
- hdhzy 9y agoWeb Assembly is specifically designed not to replace JavaScript [0]. [0]: http://webassembly.org/docs/faq/#is-webassembly-trying-to-replace-javascript http://webassembly.org/docs/faq/#is-webassembly-trying-to-re...
- _pmf_ 9y agoThat's what they have to tell to placate JS apologists.
- vesinisa 9y agoI was commenting to the GP about technologies to replace JavaScript. On the long term WASM is the best candidate, though it's indeed not one of the intended goals of the project. JS will be with us eternally, rest assured. But if DOM-enabled WASM would one day gain wide adoption, developers targeting contemporary browsers of the future would at least have a wider selection of runtimes to choose form in addition to JS.
- 9y ago
- trav4225 9y agoYup! In my personal (and basically worthless) opinion, this is why the entire "web application" ecosystem is a giant, flawed mess. It's basically what happens when a system originally designed to represent and transfer rich textual documents (HTML/HTTP) is bastardized into a application architecture. Yes, I'm being somewhat hyperbolic. Bring on the downvotes! ;-)
- peterwwillis 9y agoIt's worse than that. Because better solutions were "hard" or long-term and competing organizations couldn't agree on shared standards, they took an application and protocol designed to traverse documents, and built on complex hacks until it essentially became a pseudo-operating system, which now not only drives part of the global economy, but also changed the type and quality of information that most people receive.
- oblio 9y agoSo you're basically saying that the current web is a reflection of human kind, with all its flaws and quirks? :)
- deleted 9y ago[deleted]
- ng12 9y agoIt's a moot point. Very few professional web application developers would disagree with you. The problem is this is the world we live in and if you don't develop web applications in the consumer space you'll get eaten alive by your competitors who will.
- TheAceOfHearts 9y agoThis problem isn't limited to web applications. Think about how many security problems happen on the server. All sufficiently complex ecosystems are a giant, flawed mess.
- ef4 9y ago
- ehsankia 9y agoYou're basically letting strangers run code on your computer. That's basically what a "website" is. It is truly impressive to me how we can have something so complex and still manage to somehow keep it (usually) secure.
- moron4hire 9y agoThat's what "software" is, dude.
- sagethesagesage 9y agoThat's true, but the scale is different by orders of magnitude, and people have grown far more trusting of random websites than random software.
- softawre 9y agoCan I hire you to make quips like this during meetings when people say the most obvious shit?
- nullnilvoid 9y agoIndeed, there are so many traps you can fall into when writing web apps. It feels like when web was designed, security was not given due attention and efforts.