SE Radio 642: Simon Wijckmans on Third-Party Browser Script Security

Topics covered
Popular Clips
Questions from this episode
- Asked by 5 people
- Asked by 3 people
- Asked by 3 people
- Asked by 3 people
- Asked by 2 people
- Asked by 2 people
- Asked by 2 people
- Asked by 1 person
Episode Highlights
Polyfill Attack
The Polyfill attack serves as a stark reminder of the vulnerabilities inherent in third-party scripts. explains how the Polyfill script, initially developed by the Financial Times for cross-browser compatibility, became a target due to a change in ownership that led to malicious code injection 1. This attack redirected users to inappropriate websites, exploiting the script's widespread use across 500,000 websites 2. Simon highlights the lack of effective monitoring solutions for client-side behaviors, emphasizing the need for vigilance in managing third-party scripts 3.
The fact is we'll never know. And that's the real issue with client side security.
---
The incident underscores the importance of proactive measures to prevent such vulnerabilities from being exploited.
Vulnerabilities
Third-party scripts pose significant security risks, often overlooked by developers. Simon discusses how tools like Node Package Manager can help mitigate these risks by allowing scripts to be self-hosted, reducing dependency on external sources 4. However, the security community's reliance on threat feeds is problematic, as evidenced by the delayed response to the Polyfill incident 5. Simon advises developers to assess the reputation and reliability of script providers and to prefer self-hosting whenever possible 6.
It's not because something made it onto the Chrome Web Store that it is safe.
---
These insights highlight the need for a more cautious approach to integrating third-party scripts into web applications.
Related Episodes


SE Radio 606: Charlie Jones on Third-Party Software Supply Chain Risks
Answers 383 questions

SE Radio 568: Simon Bennetts on OWASP Dynamic Application Security Testing Tool ZAP
Answers 383 questions

SE-Radio Episode 330: Natalie Silvanovich on Attack Surface Reduction
Answers 383 questions

SE-Radio Episode 314: Scott Piper on Cloud Security
Answers 383 questions

SE-Radio Episode 302: Haroon Meer on Network Security
Answers 383 questions

Episode 427: Sven Schleier and Jeroen Willemsen on Mobile Application Security
Answers 383 questions

Episode 128: Web App Security with Bruce Sams
Answers 383 questions

SE Radio 630: Luis Rodríguez on the SSH Backdoor Attack
Answers 383 questions

SE Radio 614: Wouter Groeneveld on Creative Problem Solving for Software Development
Answers 383 questions

SE-Radio Episode 288: DevSecOps
Answers 383 questions

SE-Radio-Episode-309-Zane-Lackey-on-Application-Security
Answers 383 questions

SE Radio 584: Charles Weir on Ruthless Security for Busy Developers
Answers 383 questions

SE Radio 613: Shachar Binyamin on GraphQL Security
Answers 383 questions

SE-Radio Episode 290: Diogo Mónica on Docker Security
Answers 383 questions

SE Radio 625: Jonathan Schneider on Automated Refactoring with OpenRewrite
Answers 383 questions













