The State of JavaScript Security in 2024

Rate this content
Bookmark

As React continues to dominate the web development landscape, securing the vast ecosystem of open source dependencies has never been more critical. In 2024, the challenges around React and JavaScript security have evolved, and the risks associated with software supply chain attacks are more pronounced than ever.

In this talk, we’ll explore the current state of JavaScript security, highlighting recent high-profile supply chain attacks and their impact on the development community. We’ll discuss the latest trends, tools, and best practices for managing and securing your JavaScript dependencies.

Key topics will include:
•        An overview of recent supply chain attacks and lessons learned
•        Effective strategies for mitigating risks from malicious dependencies
•        How modern tools and standards are improving the security landscape
•        The role of developers and organizations in fostering a secure open source ecosystem

Join Feross Aboukhadijeh, a seasoned open source maintainer and security expert, as he shares insights and practical advice on navigating the complex world of JavaScript security in 2024. This session is essential for developers, security professionals, and anyone invested in maintaining a secure and resilient software supply chain.

This talk has been presented at React Summit US 2024, check out the latest edition of this React Conference.

FAQ

Transitive dependencies occur when a package you install directly depends on another package, creating a chain of dependencies throughout the dependency tree.

Dependency hell occurs when an application cannot install dependencies due to version conflicts. NPM solves this by allowing multiple versions of a package to be installed simultaneously, avoiding such conflicts.

Firas is an open source contributor with around 10 years of experience, having written about a hundred npm packages such as Web torrent and standard JS. He has also worked on polyfills used in Browserify and Webpack, and has taught a course on web security at Stanford.

JavaScript security is challenging due to the complex, intertwined technologies of modern web applications, which come with subtle security consequences. Additionally, the ecosystem is vast with many dependencies, making it susceptible to attacks.

Socket offers advanced detection of supply chain attacks and malicious code, which Dependabot does not cover. Socket analyzes every line of code in dependencies to identify potential threats.

Developers should understand their dependencies, use modern security tools, prioritize secure design, and stay informed about the OWASP top ten vulnerabilities. Hiring a pen tester is also recommended.

Socket is a tool designed to protect code by checking for vulnerabilities and malicious dependencies. It is used by various organizations to secure their repositories and prevent attacks.

Common vulnerabilities include broken access control, cryptographic failures, injection, insecure design, and vulnerable or outdated components, according to the OWASP top ten.

AI is used to analyze code for vulnerabilities, acting as a workforce to inspect dependencies. However, there are risks due to AI being trained on vulnerable code, necessitating additional checks.

The noise problem involves receiving too many alerts, many of which are false positives. Socket addresses this by prioritizing severe threats like supply chain attacks over less critical vulnerabilities.

Feross Aboukhadijeh
Feross Aboukhadijeh
32 min
19 Nov, 2024

Comments

Sign in or register to post your comment.
Video Summary and Transcription
I'm Firas, an experienced open source developer with a focus on web security. JavaScript security is challenging due to the concept of dependency hell and the reliance on open source dependencies. Vulnerable and outdated components pose a risk, and recent examples highlight the dangers in NPM. Malicious packages can remain undetected for a long time, and current tools for JavaScript security are inadequate. The speaker started Socket as a company after an interesting NPM attack in 2017. The hazards of installing unverified code are discussed, and the impact of AI on security is explored. Socket aims to address the noise problem in security alerting by focusing on the most severe vulnerabilities.

1. Introduction

Short description:

I'm Firas, an experienced open source developer with a focus on web security. I've written numerous npm packages, including Web torrent and standard JS. Now, I'm combining my expertise in open source and security with Socket, a tool that helps protect your code by checking for vulnerabilities and malicious dependencies. We have a wide range of organizations and repositories using Socket, and we are proud of the positive impact we have made.

I'm Firas, I've been doing open source for about 10 years, I've written about a hundred different npm packages, maybe some you might have heard of. Web torrent and standard JS, I did some work on some polyfills that got used in Browserify and Webpack and some other bundlers as well. Then I moved into security, I got really interested in web security, taught a course at Stanford, and now I'm kind of taking my interest in open source and security and trying to bring the two together with Socket. So I'll do just like a quick 10-20 seconds on Socket. So we help protect your code, if you need to get a tool for checking for vulnerabilities and malicious dependencies, take a look at Socket, we might be able to help. We have a bunch of organizations using us, a bunch of repos that we're protecting, and then some of our customers up here. So I'm really happy with how we've been able to help a lot of people with our product.

2. JavaScript Security Challenges

Short description:

JavaScript security is a challenging task due to the complex and interconnected nature of modern web applications. Web browsers have to allow websites to download and execute code while ensuring user safety. Despite its reputation, the web has evolved robust security measures over the years. As developers, it's crucial to understand these intricacies to build secure websites and apps. This talk aims to raise awareness and highlight important considerations for JavaScript security in 2024.

So let's talk about JavaScript security. So why is JavaScript security hard? I think the quote that kind of illustrates this is from Michael Zalewski, who is the author of The Tangled Web, which is one of the earliest web security books that I ever read. And he says, modern web applications are built on a tangle of technologies that have been developed over time and haphazardly pieced together. So every piece of the web application stack from HTTP to browser-side scripts come with important yet subtle security consequences. And to keep users safe, we really have to understand and navigate this landscape. And if you think about the job of the web browser, it's actually a seemingly impossible task. Sites, even malicious websites that you visit, can download and execute code from any IP address or origin. They can spawn worker processes in your operating system. They can open sockets, display media in any number of different formats, run code on your GPU, for goodness sakes, and save and read data from your file system. Now, would you let a malicious website do this to your computer? Well, that's what a web browser has to do. It has to let that happen safely. So it's actually amazing how robust the web is despite the reputation it sometimes gets, especially from the detractors. And so it might not have a clean design, but it's really evolved a lot of security measures to make it really robust over the years. And so, you know, it's all too easy to criticize, lament, and create paranoid scenarios about the unsound security foundations of the web. But the truth is that criticism is all true, and yet the web has proven to be incredibly robust as a platform. The thing is, though, as developers, we actually have to understand all those intricacies oftentimes in order to build secure websites and secure apps. And so that's kind of what part of this, you know, purpose of this talk is, is just to kind of raise awareness. I don't have that much time. But just to surface a few things that have sort of changed in 2024 and some things to keep in mind for you.

QnA

Check out more articles and videos

We constantly think of articles and videos that might spark Git people interest / skill us up or help building a stellar career

It's a Jungle Out There: What's Really Going on Inside Your Node_Modules Folder
Node Congress 2022Node Congress 2022
26 min
It's a Jungle Out There: What's Really Going on Inside Your Node_Modules Folder
Top Content
The talk discusses the importance of supply chain security in the open source ecosystem, highlighting the risks of relying on open source code without proper code review. It explores the trend of supply chain attacks and the need for a new approach to detect and block malicious dependencies. The talk also introduces Socket, a tool that assesses the security of packages and provides automation and analysis to protect against malware and supply chain attacks. It emphasizes the need to prioritize security in software development and offers insights into potential solutions such as realms and Deno's command line flags.
The State of Passwordless Auth on the Web
JSNation 2023JSNation 2023
30 min
The State of Passwordless Auth on the Web
Passwords are terrible and easily hacked, with most people not using password managers. The credential management API and autocomplete attribute can improve user experience and security. Two-factor authentication enhances security but regresses user experience. Passkeys offer a seamless and secure login experience, but browser support may be limited. Recommendations include detecting Passkey support and offering fallbacks to passwords and two-factor authentication.
5 Ways You Could Have Hacked Node.js
JSNation 2023JSNation 2023
22 min
5 Ways You Could Have Hacked Node.js
Top Content
The Node.js security team is responsible for addressing vulnerabilities and receives reports through HackerOne. The Talk discusses various hacking techniques, including DLL injections and DNS rebinding attacks. It also highlights Node.js security vulnerabilities such as HTTP request smuggling and certification validation. The importance of using HTTP proxy tunneling and the experimental permission model in Node.js 20 is emphasized. NearForm, a company specializing in Node.js, offers services for scaling and improving security.
Content Security Policy with Next.js: Leveling Up your Website's Security
React Summit US 2023React Summit US 2023
9 min
Content Security Policy with Next.js: Leveling Up your Website's Security
Top Content
Watch video: Content Security Policy with Next.js: Leveling Up your Website's Security
Lucas Estevão, a Principal UI Engineer and Technical Manager at Avenue Code, discusses how to implement Content Security Policy (CSP) with Next.js to enhance website security. He explains that CSP is a security layer that protects against cross-site scripting and data injection attacks by restricting browser functionality. The talk covers adding CSP to an XJS application using meta tags or headers, and demonstrates the use of the 'nonce' attribute for allowing inline scripts securely. Estevão also highlights the importance of using content security reports to identify and improve application security.
Let Me Show You How React Applications Get Hacked in the Real-World
React Advanced 2021React Advanced 2021
22 min
Let Me Show You How React Applications Get Hacked in the Real-World
Top Content
React's default security against XSS vulnerabilities, exploring and fixing XSS vulnerabilities in React, exploring control characters and security issues, exploring an alternative solution for JSON parsing, and exploring JSON input and third-party dependencies.
How React Applications Get Hacked in the Real-World
React Summit 2022React Summit 2022
7 min
How React Applications Get Hacked in the Real-World
Top Content
How to hack a RealWorld live React application in seven minutes. Tips, best practices, and pitfalls when writing React code. XSS and cross-site scripting in React. React's secure by default, but not always. The first thing to discover: adding a link to a React application. React code vulnerability: cross-site scripting with Twitter link. React doesn't sanitize or output H ref attributes. Fix attempts: detect JavaScript, use dummy hashtag, transition to lowercase. Control corrector exploit. Best practices: avoid denialist approach, sanitize user inputs. React's lack of sanitization and output encoding for user inputs. Exploring XSS vulnerabilities and the need to pretty print JSON. The React JSON pretty package and its potential XSS risks. The importance of context encoding and secure coding practices.

Workshops on related topic

Hands-On Workshop: Introduction to Pentesting for Web Apps / Web APIs
JSNation US 2024JSNation US 2024
148 min
Hands-On Workshop: Introduction to Pentesting for Web Apps / Web APIs
Featured Workshop
Gregor Biswanger
Gregor Biswanger
In this hands-on workshop, you will be equipped with the tools to effectively test the security of web applications. This course is designed for beginners as well as those already familiar with web application security testing who wish to expand their knowledge. In a world where websites play an increasingly central role, ensuring the security of these technologies is crucial. Understanding the attacker's perspective and knowing the appropriate defense mechanisms have become essential skills for IT professionals.This workshop, led by the renowned trainer Gregor Biswanger, will guide you through the use of industry-standard pentesting tools such as Burp Suite, OWASP ZAP, and the professional pentesting framework Metasploit. You will learn how to identify and exploit common vulnerabilities in web applications. Through practical exercises and challenges, you will be able to put your theoretical knowledge into practice and expand it. In this course, you will acquire the fundamental skills necessary to protect your websites from attacks and enhance the security of your systems.
0 to Auth in an hour with ReactJS
React Summit 2023React Summit 2023
56 min
0 to Auth in an hour with ReactJS
WorkshopFree
Kevin Gao
Kevin Gao
Passwordless authentication may seem complex, but it is simple to add it to any app using the right tool. There are multiple alternatives that are much better than passwords to identify and authenticate your users - including SSO, SAML, OAuth, Magic Links, One-Time Passwords, and Authenticator Apps.
While addressing security aspects and avoiding common pitfalls, we will enhance a full-stack JS application (Node.js backend + React frontend) to authenticate users with OAuth (social login) and One Time Passwords (email), including:- User authentication - Managing user interactions, returning session / refresh JWTs- Session management and validation - Storing the session securely for subsequent client requests, validating / refreshing sessions- Basic Authorization - extracting and validating claims from the session token JWT and handling authorization in backend flows
At the end of the workshop, we will also touch other approaches of authentication implementation with Descope - using frontend or backend SDKs.
OWASP Top Ten Security Vulnerabilities in Node.js
JSNation 2024JSNation 2024
97 min
OWASP Top Ten Security Vulnerabilities in Node.js
Workshop
Marco Ippolito
Marco Ippolito
In this workshop, we'll cover the top 10 most common vulnerabilities and critical security risks identified by OWASP, which is a trusted authority in Web Application Security.During the workshop, you will learn how to prevent these vulnerabilities and develop the ability to recognize them in web applications.The workshop includes 10 code challenges that represent each of the OWASP's most common vulnerabilities. There will be given hints to help solve the vulnerabilities and pass the tests.The trainer will also provide detailed explanations, slides, and real-life examples in Node.js to help understand the problems better. Additionally, you'll gain insights from a Node.js Maintainer who will share how they manage security within a large project.It's suitable for Node.js Developers of all skill levels, from beginners to experts, it requires a general knowledge of web application and JavaScript.
Table of contents:- Broken Access Control- Cryptographic Failures- Injection- Insecure Design- Security Misconfiguration- Vulnerable and Outdated Components- Identification and Authentication Failures- Software and Data Integrity Failures- Security Logging and Monitoring Failures- Server-Side Request Forgery
How to Build Front-End Access Control with NFTs
JSNation 2024JSNation 2024
88 min
How to Build Front-End Access Control with NFTs
WorkshopFree
Solange Gueiros
Solange Gueiros
Understand the fundamentals of NFT technology and its application in bolstering web security. Through practical demonstrations and hands-on exercises, attendees will learn how to seamlessly integrate NFT-based access control mechanisms into their front-end development projects.
Finding, Hacking and fixing your NodeJS Vulnerabilities with Snyk
JSNation 2022JSNation 2022
99 min
Finding, Hacking and fixing your NodeJS Vulnerabilities with Snyk
WorkshopFree
Matthew Salmon
Matthew Salmon
npm and security, how much do you know about your dependencies?Hack-along, live hacking of a vulnerable Node app https://github.com/snyk-labs/nodejs-goof, Vulnerabilities from both Open source and written code. Encouraged to download the application and hack along with us.Fixing the issues and an introduction to Snyk with a demo.Open questions.
Bring Code Quality and Security to your CI/CD pipeline
DevOps.js Conf 2022DevOps.js Conf 2022
76 min
Bring Code Quality and Security to your CI/CD pipeline
WorkshopFree
Elena Vilchik
Elena Vilchik
In this workshop we will go through all the aspects and stages when integrating your project into Code Quality and Security Ecosystem. We will take a simple web-application as a starting point and create a CI pipeline triggering code quality monitoring for it. We will do a full development cycle starting from coding in the IDE and opening a Pull Request and I will show you how you can control the quality at those stages. At the end of the workshop you will be ready to enable such integration for your own projects.