What security risks does CSS 3 create ? (also, SVG)
Posted: Tue Jun 24, 2014 5:06 pm
Hi,
Over the years CSS has evolved a lot. CSS 3 now does plenty of things including some minor calculations and animations.
I wonder, what security risk does CSS now represent ? SVG for instance can potentially be abused. Can the new CSS add to the general scriptless attack surface too ? If so, anything NoScript can do now or in a future version ?
Secondly, why doesn't NoScript have an option to add a placeholder to SVG images ? Was it conscious decision, in which case I am curious to hear the reasoning behind it, or has it just been overlooked ?
Thanks
Over the years CSS has evolved a lot. CSS 3 now does plenty of things including some minor calculations and animations.
I wonder, what security risk does CSS now represent ? SVG for instance can potentially be abused. Can the new CSS add to the general scriptless attack surface too ? If so, anything NoScript can do now or in a future version ?
Secondly, why doesn't NoScript have an option to add a placeholder to SVG images ? Was it conscious decision, in which case I am curious to hear the reasoning behind it, or has it just been overlooked ?
Thanks