USENIX Security2024Top-tier venue
Trust Me If You Can - How Usable Is Trusted Types In Practice?
Sebastian Roth, Lea Gröber, Philipp Baus, Katharina Krombholz, Ben Stock
Abstract
Many online services deal with sensitive information such as credit card data, making those applications a prime target for adversaries, e.g., through Cross-Site Scripting (XSS) attacks. Moreover, Web applications nowadays deploy their functionality via client-side code to lower the server's load, require fewer page reloads, and allow Web applications to work even if the connection is interrupted. Given this paradigm shift of increasing complexity on the browser side, client-side security issues such as client-side XSS are getting more prominent these days. A solution already deployed in server-side applications of major companies like Google is to use type-safe data, where potentially attacker-controlled string data can never be output with sanitization. The newly introduced Trusted Types API offers an analogous solution for client-side XSS. With Trusted Types, the browser enforces that no input can be passed to an execution sink without being sanitized first. Thus, a developer's only remaining task – in theory – is to create a proper sanitizer. This study aims to uncover roadblocks that occur during the deployment of the mechanism and strategies on how developers can circumvent those problems by conducting a semi-structured interview, including a coding task with 13 real-world Web developers. Our work also identifies key weaknesses in the design and documentation of Trusted Types, which we urge the standard- ization body to incorporate before the Trusted Types becomes a standard.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4fd78af1-8ccf-4eab-a6ae-7c362ab72862Cited by top-tier papers4
- "It's not my responsibility to write them": An Empirical Study of Software Product Managers and Security RequirementsHouda Naji, Felix Reichmann, Tobias Bruns, M. Angela Sasse et al.USENIX Security 2025
- Plain Text, Plain Risks: Measuring HTTP Inclusion in Android WebViews at ScalePhilipp Beer, Sebastian Roth, Martina Lindorfer, Marco SquarcinaUSENIX Security 2026
- In the DOM We Trust: Exploring the Hidden Dangers of Reading from the DOM on the WebJan Drescher, Sepehr Mirzaei, Soheil Khodayari, David Klein et al.CCS 2025
- "I have no idea how to make it safer": Studying Security and Privacy Mindsets of Browser Extension DevelopersShubham Agarwal, Rafael Mrowczynski, Maria Hellenthal, Ben StockUSENIX Security 2025
Builds on16
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Comparing the Usability of Cryptographic APIsYasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel et al.S&P 2017 · 261 citations
- "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPSKatharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. WeipplUSENIX Security 2017 · 114 citations
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 114 citations
- "If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPSKatharina Krombholz, Karoline Busse, Katharina Pfeffer, Matthew Smith et al.S&P 2019 · 105 citations
Related papers
- If It's Not Secure, It Should Not Compile: Preventing DOM-Based XSS in Large-Scale Web Development with API HardeningPei Wang, Julian Bangert, Christoph KernICSE 2021 · 9 citations
- Analyzing the Feasibility of Adopting Google's Nonce-Based CSP Solutions on WebsitesMengxia Ren, Anhao Xiang, Chuan YueICSE 2025 · 1 citation
- A Formal Security Analysis of the W3C Web Payment APIs: Attacks and VerificationQuoc Huy Do, Pedram Hosseyni, Ralf Küsters, Guido Schmitz et al.S&P 2022 · 6 citations
- A Security Study about Electron Applications and a Programming Methodology to Tame DOM FunctionalitiesZihao Jin, Shuo Chen, Yang Chen, Haixin Duan et al.NDSS 2023
- Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site ScriptingWilliam Melicher, Anupam Das, Mahmood Sharif, Lujo Bauer et al.NDSS 2018 · 84 citations
