Abstract
We conduct an analysis of access control mechanisms in the browser and note that support for mashups and defences against cross-site scripting attacks are both moving from ad-hoc measures towards solutions where the browser enforces access control policies obtained from a host (CORS and CSP respectively). We also point out the degree of trust these solutions have to take for granted.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Barth, A., Jackson, C., Mitchell, J.C.: Securing frame communication in browsers. Communications of the ACM 52(6), 83–91 (2009)
Barth, A., Veditz, D., West, M.: Content security policy 1.1. W3C Working Draft (January 2014), http://www.w3.org/TR/CSP11/
Gasser, M., Goldstein, A., Kaufman, C., Lampson, B.: The Digital distributed system security architecture. In: Proceedings of the 1989 National Computer Security Conference (1989)
Gollmann, D.: Computer Security, 3rd edn. John Wiley & Sons, Chichester (2011)
Hardy, N.: The confused deputy. Operating Systems Reviews 22(4), 36–38 (1988)
Lampson, B., Abadi, M., Burrows, M., Wobber, E.: Authentication in distributed systems: Theory and practice. ACM Transactions on Computer Systems 10(4), 265–310 (1992)
OASIS. eXtensible Access Control Markup Language (XACML) Version V3.0. Technical report, OASIS Standard (January 2013)
van Kesteren, A.: Cross-origin resource sharing. W3C Recommendation (January 2014), http://www.w3.org/TR/cors/
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2014 Springer International Publishing Switzerland
About this paper
Cite this paper
Gollmann, D. (2014). Access Control in and Around the Browser. In: Huang, X., Zhou, J. (eds) Information Security Practice and Experience. ISPEC 2014. Lecture Notes in Computer Science, vol 8434. Springer, Cham. https://doi.org/10.1007/978-3-319-06320-1_1
Download citation
DOI: https://doi.org/10.1007/978-3-319-06320-1_1
Publisher Name: Springer, Cham
Print ISBN: 978-3-319-06319-5
Online ISBN: 978-3-319-06320-1
eBook Packages: Computer ScienceComputer Science (R0)