Twitter |  Facebook |  RSS
Home Column Games Categories Internet Business Special Coverage Life & Style China View Photo News
Dec 07, 2011 00:29

HTML5 will create new challenges for security pros next year


by ivy
The move to HTML5 will enable a whole host of new Web applications, but could also create new challenges for enterprise security professionals, according to security firm Sophos. In its security predictions for 2012, Sophos...

The move to HTML5 will enable a whole host of new Web applications, but could also create new challenges for enterprise security professionals, according to security firm Sophos.

In its security predictions for 2012, Sophos identifies new Web and networking technologies -- such as HTML5 -- as one of the major security risks for the year ahead. While these technologies introduce some impressive new capabilities that are exciting for rich Web application development, they also introduce new attack vectors, the company explained.

HTML5 removes the need for most of the add-ons, because it is a more sophisticated language and comes with a full database that enables users to store gigabytes of information. So, for example, you can do full-frame animation, 3D virtual reality, or store applications inside the browser.

According to James Lyne, senior technologist at Sophos, this gets much closer to the in-client vision originally associated with cloud computing. However, by storing data within the browser, the browser becomes a target for cyber criminals.

"Traditionally the browser has been a gateway for cyber criminals to get access to your PC, now they're going to be trying to attack the browser itself to steal its data," said Lyne.

New sandboxing in HTML5 also makes "clickjacking" (tricking Web users into revealing confidential information or taking control of their computer while clicking on a seemingly innocuous link) more of a risk, as Web pages are no longer able to identify where commands are coming from.

"All that code that developers wrote to prevent applications from being automated and clickjacked by illicit parties now doesn't work," said Lyne. "They've implemented a security feature and inadvertently broken a more important one."

Furthermore, HTML raises new issues around cookies, which could make the ICO's new guidance about removing cookies after a certain period redundant.

"HTML5 could have new super-uber-cookies," said Lyne. "If people don't code their sites properly the bad guys could code a huge database of the URLs that you've been to and track all of your field input. They could potentially capture masses of information."

"Over time, HTML5 will fix many of the problems that we have, but as with any new technology you tend to get a regression in the first place," he said. "Broadly speaking, we should charge full ahead in this direction, because Flash has been a pain and the new Web apps are really cool, but we also need to make sure that we're not casually adopting a nightmare."

Coloum & Opinion

Soft Craze

Kaspersky Anti-Virus 2012: Added Cloud-Based Protection
Kaspersky Anti-Virus 2012 has become a fundamental security software chosen by millions of PC users across the globe.

Soft Craze

The ZW3D 2012 Beta is live!
ZWSOFT today unveiled the beta program for its forthcoming ZW3D 2012.

Soft Craze

Kingsoft Office Suite Professional 2012 Review
Kingsoft recently released its Kingsoft Office Suite Professional 2012.

Most Popular

Photo News

DeNA Launches Mobage for Android Beta in US, China

Yesterday’s release of Mobage for Android truly signify DeNA’s global intent.

RIM launch its latest OS7 Blackberry smartphones

RIM is expected to launch its latest OS7 smartphones any moment now.

Facebook Launches 'Facebook for Every Phone' App

Social networking giant Facebook launched a ‘Facebook for Every Phone’ app yesterday.

LittleBigPlanet 2: Move Available this Fall

It will be added Playstation Move support and available on the PlayStation Network as a DLC this fall.

2011 BrotherSoft.com All rights reserved.

About | Contact Us