An Empirical Study of the Use of Integrity Verification Mechanisms for Web Subresources
Bertil Chapuis, Olamide Omolola, Mauro Cherubini, Mathias Humbert, Kévin Huguenin
Abstract
Web developers can (and do) include subresources such as scripts, stylesheets and images in their webpages. Such subresources might be stored on content delivery networks (CDNs). This practice creates security and privacy risks, should a subresource be corrupted. The subresource integrity (SRI) recommendation, released in mid-2016 by the W3C, enables developers to include digests in their webpages in order for web browsers to verify the integrity of subresources before loading them. In this paper, we conduct the rst large-scale longitudinal study of the use of SRI on the Web by analyzing massive crawls (⇡3B URLs) of the Web over the last 3.5 years. Our results show that the adoption of SRI is modest (⇡3.40%), but grows at an increasing rate and is highly inuenced by the practices of popular library developers (e.g., Bootstrap) and CDN operators (e.g., jsDelivr). We complement our analysis about SRI with a survey of web developers (# =227): It shows that a substantial proportion of developers know SRI and understand its basic functioning, but most of them ignore important aspects of the recommendation. The results of the survey also show that the integration of SRI by developers is mostly manual -hence not scalable and error prone. This calls for a better integration of SRI in build tools. CCS CONCEPTS • Security and privacy → Web protocol security; Hash functions and message authentication codes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization FlawsKostas Drakonakis, Sotiris Ioannidis, Jason PolakisCCS 2020 · 56 citations
- The More Things Change, the More They Stay the Same: Integrity of Modern JavaScriptJohnny So, Michael Ferdman, Nick NikiforakisWWW 2023 · 7 citations
- An Empirical Study of the Usage of Checksums for Web DownloadsGaël Bernard, Rémi Coudert, Bertil Chapuis, Kévin HugueninWWW 2023 · 1 citation
- What Gets Measured Gets Managed: Mitigating Supply Chain Attacks with a Link Integrity Management SystemJohnny So, Michael Ferdman, Nick NikiforakisCCS 2025
- Who's Hosting the Block Party? Studying Third-Party Blockage of CSP and SRIMarius Steffens, Marius Musch, Martin Johns, Ben StockNDSS 2021
Builds on6
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim et al.S&P 2016 · 325 citations
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson et al.NDSS 2017 · 183 citations
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer et al.USENIX Security 2017 · 177 citations
- "If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPSKatharina Krombholz, Karoline Busse, Katharina Pfeffer, Matthew Smith et al.S&P 2019 · 105 citations
- Does Certificate Transparency Break the Web? Measuring Adoption and Error RateEmily Stark, Ryan Sleevi, Rijad Muminovic, Devon O'Brien et al.S&P 2019 · 44 citations
Related papers
- Towards Usable Checksums: Automating the Integrity Verification of Web Downloads for the MassesMauro Cherubini, Alexandre Meylan, Bertil Chapuis, Mathias Humbert et al.CCS 2018 · 11 citations
- Reining in the Web's Inconsistencies with Site PolicyStefano Calzavara, Tobias Urban, Dennis Tatang, Marius Steffens et al.NDSS 2021
- Keys on Doormats: Exposed API Credentials on the WebNurullah Demir, Yash Vekaria, Georgios Smaragdakis, Zakir DurumericCCS 2026 · 2 citations
- We Still Don't Have Secure Cross-Domain Requests: an Empirical Study of CORSJianjun Chen, Jian Jiang, Hai-Xin Duan, Tao Wan et al.USENIX Security 2018 · 30 citations
- The State of the SameSite: Studying the Usage, Effectiveness, and Adequacy of SameSite CookiesSoheil Khodayari, Giancarlo PellegrinoS&P 2022 · 28 citations
