Proceedings of the Web Conference 2020 2020
DOI: 10.1145/3366423.3380092
|View full text |Cite
|
Sign up to set email alerts
|

An Empirical Study of the Use of Integrity Verification Mechanisms for Web Subresources

Abstract: Web developers can (and do) include subresources such as scripts, stylesheets and images in their webpages. Such subresources might be stored on content delivery networks (CDNs). This practice creates security and privacy risks, should a subresource be corrupted. The subresource integrity (SRI) recommendation, released in mid-2016 by the W3C, enables developers to include digests in their webpages in order for web browsers to verify the integrity of subresources before loading them. In this paper, we conduct t… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

2
10
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
5
2

Relationship

1
6

Authors

Journals

citations
Cited by 11 publications
(12 citation statements)
references
References 29 publications
2
10
0
Order By: Relevance
“…While SRI is used on a total of 1,562 sites, we found that 626 of these only used SRI to pin popular libraries, virtually all of which were jQuery or Bootstrap (in line with what Chapuis et al [4] found). We attribute this fact mainly to the inclusion advice on the homepages of both projects, which supply HTML code snippets already, including the integrity attribute.…”
Section: B Sri In the Wildsupporting
confidence: 86%
See 2 more Smart Citations
“…While SRI is used on a total of 1,562 sites, we found that 626 of these only used SRI to pin popular libraries, virtually all of which were jQuery or Bootstrap (in line with what Chapuis et al [4] found). We attribute this fact mainly to the inclusion advice on the homepages of both projects, which supply HTML code snippets already, including the integrity attribute.…”
Section: B Sri In the Wildsupporting
confidence: 86%
“…Naturally, allowing any subdomain of a given domain increases the chances of such an endpoint being allowed. As examples show 4 , such endpoints are often contained on subdomains of widelyincluded domains, e.g., on detector.alicdn.com.…”
Section: A Host-based Allowlistsmentioning
confidence: 99%
See 1 more Smart Citation
“…And failures to address this issue can create detrimental false alarm situations. These issues are discussed in more details (for SRI) in a recent study [39].…”
Section: Subresource Integritymentioning
confidence: 99%
“…A recent study by Chapuis et al [39] shows that web developers have a strong interest in extending SRI to downloads (i.e., a elements) as well as pictures, videos, etc. We made a proposal in this direction and communicated it to W3C's WebAppSec Working Group.…”
Section: Extending Subresource Integrity To Linksmentioning
confidence: 99%