2017 USA BHB 108

Дата: 08.01.2020.

In this presentation, we will illustrate Electron’s security model and describe current isolation mechanisms to prevent untrusted content from using Node.js primitives. Electron’s IPC messaging, preloading and other internals will be comprehensively discussed. BrowserWindow and WebView security-relevant options will be also analyzed, together with design-level weaknesses and implementation bugs in Electron-based applications.

By Luca Carettoni

Full Abstract: https://www.blackhat.com/us-17/briefings/schedule/#electronegativity—a-study-of-electron-security-7320


