3 ms·
Does anyone have good additional links? I don't understand the risk of delivering an HTML document to. script tag src?
by colemickens 8y ago
Does anyone have good additional links? I don't understand the risk of delivering an HTML document to. script tag src?
- arkadiyt 8y agoThe risk is via side channel attacks like Spectre. Even if the script fails to execute (since it's html and not javascript), the html document has been loaded into the memory of the process which included the script tag, which can now start reading that memory via side channel attacks.
- h000per 8y agoThis should also help put an end to cross domain search timing attacks. An old example of one using the IMG tag: https://www.idontplaydarts.com/2015/09/cross-domain-timing-attacks-against-lucene/ https://www.idontplaydarts.com/2015/09/cross-domain-timing-a...
- tedunangst 8y agoBut chrome doesn't see the content type until after the response is served.
- untog 8y agoNo, it sees the content type in the headers that are at the start of the response. Presumably if that header isn't correct it'll stop downloading any further data.
- tedunangst 8y agoAfter Lucene has spent some variable amount of time depending on how many documents match the query...