funsec mailing list archives
Re: In Defense of HTML5
From: Michal Zalewski <lcamtuf () coredump cx>
Date: Wed, 5 Dec 2012 16:05:53 -0800
WebSockets are a concern to me. An attacker almost always wants to egress data (otherwise, what's the point?), so WebSockets are an addition to the attacker's war chest. In addition, WebSockets make it really convenient to setup reverse proxies (emphasize convenient).
Marginally so... there is a lot of web apps that handle low-latency, interactive streaming in a variety of situations, and they don't need WS for that. WS is slightly more convenient where supported, indeed, but it doesn't really enable anything that wasn't perfectly possible (and done) before. /mz _______________________________________________ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/mailman/listinfo/funsec Note: funsec is a public and open mailing list.
Current thread:
- In Defense of HTML5 Jeffrey Walton (Dec 04)
- Re: In Defense of HTML5 Stephanie Daugherty (Dec 04)
- Re: In Defense of HTML5 Paul Ferguson (Dec 04)
- Re: In Defense of HTML5 Dan Kaminsky (Dec 04)
- Re: In Defense of HTML5 Paul Ferguson (Dec 04)
- Re: In Defense of HTML5 Michal Zalewski (Dec 04)
- Re: In Defense of HTML5 Jeffrey Walton (Dec 05)
- Re: In Defense of HTML5 Michal Zalewski (Dec 05)
- Re: In Defense of HTML5 Jeffrey Walton (Dec 05)
- Re: In Defense of HTML5 Jeffrey Walton (Dec 05)
- Re: In Defense of HTML5 Stephanie Daugherty (Dec 04)