webappsec

Web Application Security Working Group repo (by w3c)

Webappsec Alternatives

Similar projects and alternatives to webappsec

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a better webappsec alternative or higher similarity.

webappsec reviews and mentions

Posts with mentions or reviews of webappsec. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-03-10.
  • How Cloudflare verifies the code WhatsApp Web serves to users
    2 projects | news.ycombinator.com | 10 Mar 2022
    It's great to hear that you want this added to browsers themselves, and you're right that browsers are more likely to implement such changes if you can show that users are deliberately installing an extension to add the missing functionality.

    There has been some discussion at the W3C about extending the SRI spec in this direction[0], but it seems they are reluctant to do that unless "multiple browser vendors" choose to implement something like this.[1] Hopefully the existence and adoption of this browser extension helps to solve that bootstrapping / Catch-22 problem.

    As for usability, would it be sufficient to just adopt a TOFU model, where the browser pins the first key it sees for a domain? To prevent the risk of permanently bricking a site (if the key gets lost, or the host gets temporarily compromised) you could politely warn the user that the key has changed, or just show a different colour icon representing that the code is correctly signed with an unknown key.

    [0] https://github.com/w3c/webappsec/issues/449

    [1] https://github.com/w3c/webappsec-subresource-integrity/issue...

Stats

Basic webappsec repo stats
1
596
7.9
11 days ago

w3c/webappsec is an open source project licensed under GNU General Public License v3.0 or later which is an OSI approved license.

The primary programming language of webappsec is HTML.

SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com