login
login
Image header Agence Europe
Europe Daily Bulletin No. 10432
Contents Publication in full By article 11 / 14
GENERAL NEWS / (ae) eu/digital

ENISA recommendations on new web standards

Brussels, 02/08/2011 (Agence Europe) - At a crucial time in the development of HRML5, the new core standard for the internet, the European Network and Information Security Agency (ENISA) proposed on Monday 1 August major security fixes for 13 upcoming web standards. ENISA has identified 50 security threats and suggested how they should be addressed.

Banking, social networking, shopping, navigation, card payments and even managing critical infrastructure such as power networks now takes place within a browser window. “The web browser is now one of the most security-critical components in our information infrastructure - an increasingly lucrative target for cyber-attackers”, Udo Helmbrecht, ENISA Executive Director, has said.

The W3C (Worldwide Web Consortium) is currently working on important revision of its core standards. ENISA has reviewed these specifications and suggested improvements aimed at enhancing browser security for all web users.

The ENISA analysis reveals 50 threats and security problems including: - unprotected access to sensitive information; - new ways to trigger form-submission to attackers; - problems in specifying and enforcing security policies; - potential mismatches with operation system permission management; - underspecified features, potentially leading to conflicting or error-prone implementations; - and new ways to escape access control mechanisms and protection from “click-jacking” (tricking the user into clicking on dangerous links and buttons). (L.C/G.Ba/transl.jl)