Notice: file_put_contents(): Write of 7573 bytes failed with errno=28 No space left on device in /var/www/tg-me/post.php on line 50
Solidot | Telegram Webview: solidot/26818 -
Telegram Group & Telegram Channel
加固 Firefox 前端

2025-04-10 14:23 by 蒲公英王朝2:风暴之墙

Firefox Application Security Team 安全团队在其博客 Attack & Defense 上发表文章,介绍了在加固 Firefox 前端上所做的工作。Firefox 的大部分 UI 是使用标准 Web 技术如 HTML、CSS 和 JavaScript 实现的,这么做的好处是可以在所有桌面操作系统上使用浏览器引擎渲染前端,缺陷是容易受到注入攻击。最常见的注入攻击是跨站脚本(Cross-Site Scripting 简写 XSS)攻击。为缓解 Firefox UI 的 XSS 和其它注入攻击,安全团队重新了逾 600 个 JavaScript 事件处理程序。这些代码将应用于 Firefox 下一个版本 v138(目前的稳定版本是 Firefox 137)。安全团队表示通过消除一整类攻击类型,他们大幅提高了攻击者利用 Firefox 的门槛。

Attack & Defense:Hardening the Firefox Frontend with Content Security Policies

#Firefox



tg-me.com/solidot/26818
Create:
Last Update:

加固 Firefox 前端

2025-04-10 14:23 by 蒲公英王朝2:风暴之墙

Firefox Application Security Team 安全团队在其博客 Attack & Defense 上发表文章,介绍了在加固 Firefox 前端上所做的工作。Firefox 的大部分 UI 是使用标准 Web 技术如 HTML、CSS 和 JavaScript 实现的,这么做的好处是可以在所有桌面操作系统上使用浏览器引擎渲染前端,缺陷是容易受到注入攻击。最常见的注入攻击是跨站脚本(Cross-Site Scripting 简写 XSS)攻击。为缓解 Firefox UI 的 XSS 和其它注入攻击,安全团队重新了逾 600 个 JavaScript 事件处理程序。这些代码将应用于 Firefox 下一个版本 v138(目前的稳定版本是 Firefox 137)。安全团队表示通过消除一整类攻击类型,他们大幅提高了攻击者利用 Firefox 的门槛。

Attack & Defense:Hardening the Firefox Frontend with Content Security Policies

#Firefox

BY Solidot


Warning: Undefined variable $i in /var/www/tg-me/post.php on line 283

Share with your friend now:
tg-me.com/solidot/26818

View MORE
Open in Telegram


Solidot Telegram | DID YOU KNOW?

Date: |

Should I buy bitcoin?

“To the extent it is used I fear it’s often for illicit finance. It’s an extremely inefficient way of conducting transactions, and the amount of energy that’s consumed in processing those transactions is staggering,” the former Fed chairwoman said. Yellen’s comments have been cited as a reason for bitcoin’s recent losses. However, Yellen’s assessment of bitcoin as a inefficient medium of exchange is an important point and one that has already been raised in the past by bitcoin bulls. Using a volatile asset in exchange for goods and services makes little sense if the asset can tumble 10% in a day, or surge 80% over the course of a two months as bitcoin has done in 2021, critics argue. To put a finer point on it, over the past 12 months bitcoin has registered 8 corrections, defined as a decline from a recent peak of at least 10% but not more than 20%, and two bear markets, which are defined as falls of 20% or more, according to Dow Jones Market Data.

A Telegram spokesman declined to comment on the bond issue or the amount of the debt the company has due. The spokesman said Telegram’s equipment and bandwidth costs are growing because it has consistently posted more than 40% year-to-year growth in users.

Solidot from us


Telegram Solidot
FROM USA