Web asset security
and how to verify that Javascript before you trust your data to it
Presented by:
Adam Majer
Adam Majer
from
SUSE Linux
No video of the event yet, sorry!
Before downloading a software release, we all know to verify the GPG signature before even trying to unpack that tarball. And when such a signature is not available, we all know to chastise the developer for not taking security seriously. But what happens with deployed web resources? How can these be verified before we trust them with our secure data?
I would like to show a proof-of-concept of using out-of-band verification (aka, DNS) of web content (.js, .html, .jpeg, etc) prior to allowing it to execute and trusting it with our data.
- Date:
- 2022 June 3 - 17:30
- Duration:
- 25 min
- Room:
- Seminarraum 1
- Conference:
- openSUSE Conference 2022
- Language:
- English
- Track:
- New Technologies
- Difficulty:
- Medium