Research

Client-side web security

 

In the modern web, multiple parties are involved in delivering web applications into your browser. Web sites heavily rely on JavaScript from third parties, and cross-domain requests are ubiquitous in normal browsing behavior.FlowFox ensures that sensitive information in your browser never leaks by employing a novel technique called Secure Multi-Execution. FlowFox is an information-flow enhanced browser, based on Firefox, and is freely available for download.Both mechanisms are important enablers of current web technology, but are often misused for stealing sensitive data or launching transactions on behalf of the unaware website visitor.
CsFire, a free extension for Firefox and Chrome, offers user-friendly protection against malicious cross-domain requests by preventing the automatic attachment of authentication credentials. FlowFox ensures that sensitive information in your browser never leaks by employing a novel technique called Secure Multi-Execution. FlowFox is an information-flow enhanced browser, based on Firefox, and is freely available for download.