HTML5 vs. Security

Why Cross-Site Scripting becomes even worse

HTML5 is the new upcoming web standard which introduces several new features that can be used by web applications and web browsers. Through these new features new vulnerabilities are introduced as well. While in HTML 4.01 the attacks mainly focus on web servers, with HTML5 this boundary has moved towards the client. New HTML5 features enable possibilities for directly attacking the web browser and not all can be circumvented by secure implementation on the server side, because some HTML5 features are the vulnerabilities itself.

SPEAKER Thomas Röthlisberger, Compass Security AG

LEVEL OF TALK Intermediate
LANGUAGE Talk: de / Slides: en

