4 ms·
Want to know how you can easily stop this attack? What I've done here is add the SRI Integrity Attribute and that allows the browser to determine if th
by cbr 9y ago
Want to know how you can easily stop this attack? What
I've done here is add the SRI Integrity Attribute and
that allows the browser to determine if the file has
been modified, which allows it to reject the file.
SRI does not fix this problem. If you put an integrity attribute on the script, then the next time BrowseAloud releases to prod their script will stop working on your site.
This is a product that works by running a script on your page to make changes. There's no option for defense in depth here: either you trust that their processes are secure enough that they're not going to XSS you, or you shouldn't run their code on your site at all.
The bar for including javascript from other sites should be a high one, but there are times when the tradeoff is reasonable. For example, I have Google Analytics [1] on my site, and I trust them to handle this responsibly.
[1] Disclosure: I now work for Google
- Kenji 9y agoI really see no reason why anyone would include JS files from other sites. I regularly see people including jquery from google or other sources. Why the hell? You can't host a little JavaScript file yourself? What's wrong with web devs these days??
- gambler 9y ago>The bar for including javascript from other sites should be a high one Yes, but that's not how most developers think these days. Try browsing the Web with NoScript and you will routinely witness dozens of domains in the block list.
- throwawaypanda 9y ago>The bar for including javascript from other sites should be a high one >but that's not how most developers think these days. The decision to include third party javascript is sometimes not even up to developers these days. "A deal has been signed with company X, put their widget on the site" is something I've now heard a few times. Arguments about the third party code greatly increasing page load time, page size, introducing security vulnerabilities etc then fall on deaf ears. High developer turnover seems to co-occur in these environments.
- arkh 9y ago> For example, I have Google Analytics [1] on my site, and I trust them to handle this responsibly. I don't. And I don't appreciate people injecting Google beacons on their website. Same thing with Facebook, Twitter, Disqus and all the other shit-scripts.