安全
Here are my papers and ideas on web 安全, with a particular 強調 on web browsers. However, most of them are now rather old. I work on CA stuff for Mozilla, and most of the thinking and 令状ing I do in this area is now in that 状況.
証明書s
- Firefox and Self-調印するd Certs - a defence of the Firefox 証明書 UI.
Phishing
- A 計画(する) For Scams - a 要約 of the work that needs doing to 保護する Internet 使用者s from phishing.
- 改善するing Authentication On The Internet - another paper analysing the phishing 脅し, and looking at 現在の 科学(工学)技術s ーに関して/ーの点でs of privacy, validation and authentication.
- Staying 安全な From Phishing With Firefox - my "spec" for Firefox's anti-phishing 成果/努力s.
- Phishing - Browser-based Defences - a 調査する of possible changes to browsers to better 保護する against phishing. It 含む/封じ込めるs two 重要な ideas:
- New 場所/位置 - show 使用者s if they've visited a particular SSL 場所/位置 before.
- Phish Finder - discussion of the 機械装置s and heuristics for an in-browser phishing 場所/位置 detector.
Cross-場所/位置 Scripting
- Content 制限s - mitigate XSS attacks by 許すing 場所/位置s to 明示する the 能力s script on their pages should have. Many of the ideas from this have 設立する their way into CSP.
- Script 重要なs - mitigate XSS attacks by 許すing 場所/位置s to 明示する which scripts on their pages should run. This idea also 結局 made its way into CSP.
Other
- Link 指紋s - 確実にする a downloaded とじ込み/提出する is the exact 要求するd 見解/翻訳/版 by embedding a checksum in the link to it.