18 October 2011

HTML5 Security

OWASP has announced a new addition to the immensely helpful cheat sheet series.

This first version of the HTML Security Cheat Sheet includes guidance on:

  • Cross Origin Resource Sharing
  • Local Storage (a.k.a. Offline Storage, Web Storage)
  • WebDatabase
  • Web Workers
  • WebSockets
  • Geolocation
  • Use the sandbox attribute of an iframe for untrusted content
  • Web Messaging
  • XHR and DOM abuses
  • HTML5 Widgets
  • Progressive Enhancements and Graceful Degradation Risks

If you have anything to add, or suggest, please contact the people involved — Mark Roxbury, Krzysztof Kotowicz, Will Stranathan and Shreeraj Shah are the authors and primary editors.

For something in more depth, go to html5security and the related html5sec for an encyclopaedic reference source.

There is another more general presentation about using HTML5 WebSockets at London Web on Thursday evening this week (20th October), but be quick to register as there are already 175 people attending, and currently only 4 spaces left.

Posted on: 18 October 2011 at 13:30 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
HTML5 Security
http://www.clerkendweller.com/2011/10/18/HTML5-Security
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2011/10/18/HTML5-Security
Requested by 107.22.156.205 on Saturday, 25 May 2013 at 21:50 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2011-2013 clerkendweller.com