Tag. security
Notes (1)
Cloudflare Parsing Error cloudflare-parsing-error
An error in the Cloudflare HTML parser would allow uninitialized memory to be dumped when there were imbalanced HTML tags.
This is indeed a case where a verified parser would have alleviated the issue.
References (24)
Cerisier: A Program Logic for Attestation in a Capability Machine rousseau-2026-cerisier
Confidential computing for population-scale genome-wide association studies with SECRET-GWAS rosenblum-2025-confidential
ZIPNet: Low-bandwidth anonymous broadcast from (dis)Trusted Execution Environments rosenberg-2025-zipnet
Hybrid Obfuscated Key Exchange and KEMs gunther-2025-hybrid
PAKE Combiners and Efficient Post-quantum Instantiations hesse-2025-pake
Hekaton: Horizontally-Scalable zkSNARKs Via Proof Aggregation rosenberg-2024-hekaton
Toleo: Scaling Freshness to Tera-scale Memory Using CXL and PIM dong-2024-toleo
Cerise: Program Verification on a Capability Machine in the Presence of Untrusted Code georges-2024-cerise
LATKE: A Framework for Constructing Identity-Binding PAKEs katz-2024-latke
Security Verification of Low-Trust Architectures tan-2023-security
Galápagos: Developing Verified Low Level Cryptography on Heterogeneous Hardwares zhou-2023-galapagos
Curbing the Vulnerable Parser: Graded Modal Guardrails for Secure Input Handling bond-2023-curbing
Siloz: Leveraging DRAM Isolation Domains to Prevent Inter-VM Rowhammer loughlin-2023-siloz
Owl: Compositional Verification of Security Protocols via an Information-Flow Type System gancher-2023-owl
zk-creds: Flexible Anonymous Credentials from zkSNARKs and Existing Identity Infrastructure rosenberg-2023-zk
SNARKBlock: Federated Anonymous Blocklisting from Hidden Common Input Aggregate Proofs rosenberg-2022-snarkblock
Labeled PSI from Homomorphic Encryption with Reduced Computation and Communication cong-2021-labeled
Boosting the Security of Blind Signature Schemes katz-2021-boosting
First-Order Logic for Flow-Limited Authorization hirsch_etal_2020
Fission: Secure Dynamic Code-Splitting for JavaScript guha-2017-fission
Traditional web programming involves the creation of two distinct programs: a client-side front-end, a server-side back-end, and a lot of communications boilerplate. An alternative approach is to use a tierless programming model, where a single program describes the behavior of both the client and the server, and the runtime system takes care of communication. Unfortunately, this usually entails adopting a new language and thus abandoning well-worn libraries and web programming tools.
In this paper, we present our ongoing work on Fission, a platform that uses dynamic tier-splitting and dynamic information flow control to transparently run a single JavaScript program across the client and server. Although static tier-splitting has been studied before, our focus on dynamic approaches presents several new challenges and opportunities. For example, Fission supports characteristic JavaScript features such as eval and sophisticated JavaScript libraries like React. Therefore, programmers can reason about the integrity and confidentiality of information while continuing to use common libraries and programming patterns. Moreover, by unifying the client and server into a single program, Fission allows language-based tools, like type systems and IDEs, to manipulate complete web applications. To illustrate, we use TypeScript to ensure that client-server communication does not go wrong.