BlueHat IL 2024 - Gal Weizman - DOM Jungle - Can We Trust The UI?

  Рет қаралды 110

Microsoft Israel R&D Center

Microsoft Israel R&D Center

21 күн бұрын

One thing's for sure - we can no longer trust all code running under the same origin as our app because of today's landscape of development where web apps are mostly composed of third party code that builders do not control.
Thus, we can no longer trustfully perform many operations we're used to blindly trust. A significant one being DOM interaction - if some code I don't trust runs in my app, how can I rest assured it doesn't manipulate the DOM and the content accessible to the user? If I present them with sensitive content, can an attacker just steal it? What stops them from changing my website's layout to phish the user?
Regulating DOM restriction is a very hard problem to solve due to how it's designed.
In this talk, we'll make it clear why DOM API is so complicated to confine, explain why this problem is so concerning, and explore noble approaches for addressing it such as SnowJS, LavaDome and LavaMoat and how they open up new possibilities for finally safely working with the DOM.

Пікірлер
Why I Quit Java (as a Java Developer)
4:56
Tom Gregory Tech
Рет қаралды 16 М.
Опасность фирменной зарядки Apple
00:57
SuperCrastan
Рет қаралды 10 МЛН
50 YouTubers Fight For $1,000,000
41:27
MrBeast
Рет қаралды 205 МЛН
יום העצמאות ה-76: לכו תסבירו מה זה להיות ישראלים
1:42
BlueHat IL 2024 - Dor Amit - BlueHawk - The Bluetooth Motion Detector
26:29
Microsoft Israel R&D Center
Рет қаралды 43
BlueHat IL 2024 - Ori David - Hi! My Name Is [What?]: Abusing Microsoft DHCP to...
37:18
Новые iPhone 16 и 16 Pro Max
0:42
Romancev768
Рет қаралды 2,1 МЛН
iPhone 15 Pro Max vs IPhone Xs Max  troll face speed test
0:33
АЙФОН 20 С ФУНКЦИЕЙ ВИДЕНИЯ ОГНЯ
0:59
КиноХост
Рет қаралды 1,2 МЛН
S24 Ultra and IPhone 14 Pro Max telephoto shooting comparison #shorts
0:15
Photographer Army
Рет қаралды 10 МЛН