Tainted Secure Multi-Execution to Restrict Attacker Influence

McKenna McCall, Abhishek Bichhawat, Limin Jia · 2023

Attackers can steal sensitive user information from web pages via third-party scripts. Prior work shows that secure multi-execution (SME) with declassification is useful for mitigating such attacks, but that attackers can leverage dynamic web features to declassify more than intended. The proposed solution of disallowing events from dynamic web elements to be declassified is too restrictive to be practical; websites that declassify events from dynamic elements cannot function correctly.

Read the paper · More papers on PaperTik