Главная
Study mode:
on
1
Introduction
2
What is HTML5
3
Mobile applications
4
Authentication
5
Multifactor
6
Flash Cookies
7
Surf Crosstalk
8
Risks
9
Opera Mini
10
Canvas
11
Interactive Login
12
Connect Dots
13
Android Pattern
14
Demo
15
Canvas Support
16
Mobile Devices
17
Geolocation
18
Browser fingerprinting
19
Face recognition
20
Face detection API
21
Supported devices
22
Accelerometer
23
Popup notifications
24
Crypto
25
How it works
26
Summary
Description:
Explore the security implications of HTML5 in this 51-minute conference talk by Johannes Ullrich, presented by the OWASP Foundation. Delve into the new subsystems introduced by HTML5 and their impact on web application security. Learn how features like client-side data storage and hardware sensor access can enhance session tracking and improve authentication. Examine code samples and demonstrations that highlight both positive and negative security effects. Cover topics including mobile applications, multifactor authentication, Flash cookies, surf crosstalk risks, Opera Mini, canvas fingerprinting, geolocation, face recognition, accelerometer usage, popup notifications, and cryptography. Gain insights from Ullrich's extensive experience as a research physicist and web developer, and discover how HTML5 can be leveraged as a hidden security tool chest.

HTML5 - Security Risks and Tools in Modern Web Applications

OWASP Foundation
Add to list
0:00 / 0:00