×
Copy
Open
Link
Embed
Share
Beginning
This slide
Copy link URL
Copy link URL
Copy iframe embed code
Copy iframe embed code
Copy javascript embed code
Copy javascript embed code
Share
Tweet
Share
Tweet
Slide 1
Slide 1 text
Web Platform Security Leveling up Jérémy Courtial Software Security Architect
Slide 2
Slide 2 text
_______ : noun [c]. An application entirely dedicated to execute unknown code from unknown origin.
Slide 3
Slide 3 text
_______ : noun [c]. An application entirely dedicated to execute unknown code from unknown origin. Rootkit ?
Slide 4
Slide 4 text
_______ : noun [c]. An application entirely dedicated to execute unknown code from unknown origin. Malware ?
Slide 5
Slide 5 text
_______ : noun [c]. An application entirely dedicated to execute unknown code from unknown origin. Trojan ?
Slide 6
Slide 6 text
_______ : noun [c]. An application entirely dedicated to execute unknown code from unknown origin. Browser /ˈbraʊ.zɚ/
Slide 7
Slide 7 text
http://yolo.com Go!
Slide 8
Slide 8 text
curl -s http://yolo.com | sh VS http://yolo.com Go!
Slide 9
Slide 9 text
Browser : noun [c]. /ˈbraʊ.zɚ/ An application entirely dedicated to execute unknown code from unknown origin.
Slide 10
Slide 10 text
Unknown origin
Slide 11
Slide 11 text
Unknown origin Unsecure
Slide 12
Slide 12 text
What is anyway ? www.google.com
Slide 13
Slide 13 text
What is anyway ? www.oodrive.com
Slide 14
Slide 14 text
What is anyway ? www.lol-cats.com
Slide 15
Slide 15 text
What is anyway ? 172.217.20.46
Slide 16
Slide 16 text
Unsecure origin
Slide 17
Slide 17 text
Unsecure origin
Slide 18
Slide 18 text
Transport Layer Security
Slide 19
Slide 19 text
Confidentiality Integrity Authentication
Slide 20
Slide 20 text
Other incentives "The green lock™"
Slide 21
Slide 21 text
Other incentives HTTP/2
Slide 22
Slide 22 text
Other incentives "Secure origins only" features
Slide 23
Slide 23 text
http https
Slide 24
Slide 24 text
GET /
Slide 25
Slide 25 text
GET / 302 Found Location: https://yolo.com
Slide 26
Slide 26 text
GET / 302 Found Location: https://yolo.com
Slide 27
Slide 27 text
No content
Slide 28
Slide 28 text
No content
Slide 29
Slide 29 text
302 Found
Slide 30
Slide 30 text
302 Found
Slide 31
Slide 31 text
302 Found
Slide 32
Slide 32 text
HTTP Strict Transport Security
Slide 33
Slide 33 text
Strict-Transport-Security :
Slide 34
Slide 34 text
max-age=31536000; Strict-Transport-Security :
Slide 35
Slide 35 text
includeSubdomains; max-age=31536000; Strict-Transport-Security :
Slide 36
Slide 36 text
http://yolo.com
Slide 37
Slide 37 text
http://yolo.com 307 Internal Redirect
Slide 38
Slide 38 text
https://yolo.com 307 Internal Redirect
Slide 39
Slide 39 text
307 Internal Redirect GET / https://yolo.com
Slide 40
Slide 40 text
Trust failure
Slide 41
Slide 41 text
TLS certificates are based on trust
Slide 42
Slide 42 text
Oh… trust … That's cute …
Slide 43
Slide 43 text
Trust-based systems don't have a good reliability record …
Slide 44
Slide 44 text
Certificate Authority failures Bad captive portal Every "Internal CA"
Slide 45
Slide 45 text
You've failed me for the last time
Slide 46
Slide 46 text
HTTP Certificate Pinning
Slide 47
Slide 47 text
Public-Key-Pins:
Slide 48
Slide 48 text
Public-Key-Pins: pin-sha256="d6qzRu9zO…YYkVoZWmM=";
Slide 49
Slide 49 text
Public-Key-Pins: pin-sha256="d6qzRu9zO…YYkVoZWmM="; pin-sha256="E9KB9INbd…xcMF+44U1g=";
Slide 50
Slide 50 text
Public-Key-Pins: pin-sha256="d6qzRu9zO…YYkVoZWmM="; pin-sha256="E9KB9INbd…xcMF+44U1g="; report-uri="http://example.com/pkp-report";
Slide 51
Slide 51 text
max-age=259200; Public-Key-Pins: pin-sha256="d6qzRu9zO…YYkVoZWmM="; pin-sha256="E9KB9INbd…xcMF+44U1g="; report-uri="http://example.com/pkp-report";
Slide 52
Slide 52 text
includeSubDomains; max-age=259200; Public-Key-Pins: pin-sha256="d6qzRu9zO…YYkVoZWmM="; pin-sha256="E9KB9INbd…xcMF+44U1g="; report-uri="http://example.com/pkp-report";
Slide 53
Slide 53 text
_______ : noun [c]. /ˈbraʊ.zɚ/ An application entirely dedicated to execute unknown code from Browser _______ : noun [c]. /ˈbraʊ.zɚ/ An application entirely dedicated to execute unknown code from unknown origin.
Slide 54
Slide 54 text
_______ : noun [c]. /ˈbraʊ.zɚ/ An application entirely dedicated to execute unknown code from Browser _______ : noun [c]. /ˈbraʊ.zɚ/ An application entirely dedicated to execute unknown code from secured origins.
Slide 55
Slide 55 text
Unknown code
Slide 56
Slide 56 text
XSS
Hello, ${username}
Slide 57
Slide 57 text
XSS $username = "
"
Slide 58
Slide 58 text
XSS
Hello,
Slide 59
Slide 59 text
CSRF https://evil.com Click here!
Slide 60
Slide 60 text
CSRF good.com/post
Slide 61
Slide 61 text
CSRF good.com/post
Slide 62
Slide 62 text
CSRF good.com/post
Slide 63
Slide 63 text
Everybody love cookies !
Slide 64
Slide 64 text
Rename Cookie to Spinach ?
Slide 65
Slide 65 text
Rename Cookie to Spinach ? Brussel Sprout ?
Slide 66
Slide 66 text
REJECTED
Slide 67
Slide 67 text
Locking the cookie jar
Slide 68
Slide 68 text
Set-Cookie : JSESSIONID=12345;
Slide 69
Slide 69 text
Set-Cookie : JSESSIONID=12345; secure;
Slide 70
Slide 70 text
Set-Cookie : JSESSIONID=12345; secure; HttpOnly;
Slide 71
Slide 71 text
Set-Cookie : JSESSIONID=12345; sameSite = strict | lax; secure; HttpOnly;
Slide 72
Slide 72 text
Content Security Policy
Slide 73
Slide 73 text
Content-Security-Policy
Slide 74
Slide 74 text
: default-src 'none'; script-src 'self' 'api.google.com'; style-src … ; form-src … ; connect-src …; Content-Security-Policy
Slide 75
Slide 75 text
: … report-uri …; script-src 'strict-dynamic' …; upgrade-insecure-requests; … Content-Security-Policy
Slide 76
Slide 76 text
Our data (cookies, assets) are locked. What about third parties ?
Slide 77
Slide 77 text
HTML JS JPG
Slide 78
Slide 78 text
CDN HTML JS JPG JS JPG
Slide 79
Slide 79 text
CDN HTML JS JPG JS JPG
Slide 80
Slide 80 text
CDN HTML JS JPG JS JPG
Slide 81
Slide 81 text
CDN HTML JS JPG JS JPG
Slide 82
Slide 82 text
Subresource Integrity
Slide 83
Slide 83 text
Slide 84
Slide 84 text
integrity="sha384-oqVuAfXR….Y8wC">
Slide 85
Slide 85 text
_______ : noun [c]. /ˈbraʊ.zɚ/ An application entirely dedicated to execute unknown code from secured origins Browser unknown code
Slide 86
Slide 86 text
_______ : noun [c]. /ˈbraʊ.zɚ/ An application entirely dedicated to execute unknown code from secured origins Browser trusted code
Slide 87
Slide 87 text
Many more Suborigins iframe sandboxing Credentials Management
Slide 88
Slide 88 text
https://www.w3.org/2011/webappsec/ @mikewest
Slide 89
Slide 89 text
Times have changed
Slide 90
Slide 90 text
Times have changed "secured" is the new default secured
Slide 91
Slide 91 text
What does secured means ? secured Least Privilege Authentication Integrity
Slide 92
Slide 92 text
Is our platform ? secured
Slide 93
Slide 93 text
Thank you Icons from Ismael Ruiz, Konstantin Velichko, Rémy Médard, unlimicon (The Noun Project) and design.google.com/icons/