On the Incoherencies in Web Browser Access Control Policies

IEEE Symposium on Security and Privacy, pp. 463-478, 2010.

Cited by: 94|Views39


Web browsers' access control policies have evolved piecemeal in an ad-hoc fashion with the introduction of new browser features. This has resulted in numerous incoherencies. In this paper, we analyze three major access control flaws in today's browsers: (1) principal labeling is different for different resources, raising problems when res...More



