3 ms·
It's possible to define the Content Security Policy with a <META> tag in the "bootstrap page" and prevent this kind of security issue, e.g. <META http-equiv="co
by gildas 2y ago
It's possible to define the Content Security Policy with a <META> tag in the "bootstrap page" and prevent this kind of security issue, e.g. <META http-equiv="content-security-policy" content="connect-src 'self' data: blob:;">
- Thorrez 2y agoI don't think that will prevent data exfiltration. Malicious javascript could create e.g. an img element with the data to exfiltrate stored in a query parameter of the image URL.
- gildas 2y agoThe request will be blocked by the CSP.
- Thorrez 2y agoWhy? The CSP policy isn't setting default-src or img-src. So image loads are allowed from everywhere.
- gildas 2y agoThat was just an example of syntax, nothing prevents you from blocking more resources and sandbox the page.
- Thorrez 2y agoIf we make it strict enough to block exfiltration, it'll block the external libraries from loading. So that means we have to load our scripts from the same origin instead of external origins (as jclarkcom suggested). But the whole reason for CSP was to allow us to use external libraries without exfiltration risk. If we stop using external libraries, then our motivation for using CSP is gone. So CSP is useless for the purpose of this conversation.
- gildas 2y agoI think there's been a misunderstanding, there was an error in the article suggesting that zip.min.js is not inlined in the page. This error has been corrected meanwhile. I'm sorry for that. The goal is obviously to create pages that work offline, as shown in the demo.
- infotogivenm 2y agosource integrity is probably the more applicable feature for gp’s concerns