Basic HTML version of Foils prepared April 7 1998

Foil 114 JavaScript Security Issues

From Basic Principles of Java and Internet Security CPS616 Web Technologies -- Spring 98. by Geoffrey C. Fox


Signed Script Policy comes with Netscape version 4.
In Navigator 3.0, one could use data tainting to get access to additional information.
  • This was very clumsy and almost impossible to use and in particular to make precise
However, Navigator 4.0 replaces data tainting with the signed script policy. Because signed scripts provide greater security and greater precision than tainting, tainting has been disabled in Communicator 4.x.



© Northeast Parallel Architectures Center, Syracuse University, npac@npac.syr.edu

If you have any comments about this server, send e-mail to webmaster@npac.syr.edu.

Page produced by wwwfoil on Sun Nov 29 1998