Phew, what a week! Due to an HTML-parsing bug, Cloudflare experienced a major data leak, and the first practical collision for SHA-1 was revealed as well. We should take these events as an occasion to reconsider if a centralized front-end load balancer that modifies your traffic is a good idea after all. And it’s definitely time to upgrade your TLS-certificate if you still serve SHA-1, too. Here’s what else happened this week.
Further Reading on SmashingMag: Link
- Next Generation Server Compression With Brotli1
- Making Accessibility Simpler, With Ally.js2
- Team Collaboration And Closing Efficiency Gaps In Responsive Design3
- A Simple Workflow From Development To Deployment4
- Cloudflare experienced a memory leak caused by its document parser5. Here is the incident report by Cloudflare6.
- The fresh Safari Technology Preview 247 added support for PerformanceObserver and added
importoperator and suspended SVG animations on hidden pages.
- It was just a matter of time until browsers would stop accepting SHA-1 certificates. But this week, things took a sudden turn as Google researchers revealed the first practical collision for SHA-1, affirming the insecurity of the algorithm. As a result of this, starting from today, Mozilla will remote-update Firefox to not accept SHA-1 in certificates anymore8.
- How does your team review code? Ana Balica shares a useful checklist for reviewing your and your teammates code9.
Tools & Workflows Link
- Joseph Zimmerman introduces us to Webpack10. What I really like about this article is that it’s not another article sharing pre-built sets of configurations but that it explains every detail step-by-step.
- Oh shit, git!11 Don’t be afraid of git anymore thanks to this emergency guide that helps you solve the most common problems with the versioning system.
- Mitigating Cross-Site Request Forgery attacks has never been easy. Luckily, it seems that we now got a proper solution for it: Same-Site Cookies14. The only thing you need to do to make it work is adding
SameSiteto your existing
Set-Cookieheader. Of course, you should know how same-site cookies differ from “normal” cookies, but for most sites this should be easy to implement.
- A joint-venture of five journalists researched how the private security industry works and what price we as citizens pay for our security15.
- It’s not your computer that is the most vulnerable device, it’s your smartphone. In fact, for a small amount of money, everyone can easily buy spyware16 that works on most Android phones. For iOS, things look a bit better unless the device is jailbroken. But this doesn’t necessarily mean that spyware doesn’t exist for that system as well.
Web Performance Link
- Thadee Trompetter shares insights into how Brotli can improve your site’s performance17 and why he relies on pre-compressing rather than doing it on the fly on the server.
Going Beyond… Link
- A team at the MIT Media Lab invented a device that captures air pollution and turns the pollution into safe, high-quality ink for art21.
- The Institute For Energy Efficiency’s computing solutions group has a couple of interesting projects and data to share. For example, they try to figure out solutions to selectively shut down unnecessary components while retaining access to critical data. This is only one of their ambitious projects and shows how much potential there is when it comes to improving energy efficiency in our networks22.
And with that, I’ll close for this week. If you like what I write each week, please support me with a donation25 or share this resource with other people. You can learn more about the costs of the project here26. It’s available via email, RSS and online.
- 1 https://www.smashingmagazine.com/2016/10/next-generation-server-compression-with-brotli/
- 2 https://www.smashingmagazine.com/2015/12/making-accessibility-simpler/
- 3 https://www.smashingmagazine.com/2014/05/team-collaboration-closing-efficiency-gaps-responsive-design/
- 4 https://www.smashingmagazine.com/2015/07/development-to-deployment-workflow/
- 5 https://bugs.chromium.org/p/project-zero/issues/detail?id=1139
- 6 https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/
- 7 https://webkit.org/blog/7423/release-notes-for-safari-technology-preview-24/
- 8 https://blog.mozilla.org/security/2017/02/23/the-end-of-sha-1-on-the-public-web/
- 9 https://ana-balica.github.io/2017/02/21/code-review-checklist/
- 10 https://www.smashingmagazine.com/2017/02/a-detailed-introduction-to-webpack/
- 11 http://ohshitgit.com/
- 12 http://ohshitgit.com/
- 13 http://ohshitgit.com/
- 14 https://scotthelme.co.uk/csrf-is-dead/
- 15 https://thecorrespondent.com/10221/security-for-sale-the-price-we-pay-to-protect-europeans
- 16 https://motherboard.vice.com/en_us/article/i-tracked-myself-with-dollar170-smartphone-spyware-that-anyone-can-buy
- 17 https://www.voorhoede.nl/en/blog/static-site-implosion-with-brotli-and-gzip/
- 18 https://www.voorhoede.nl/en/blog/static-site-implosion-with-brotli-and-gzip/
- 19 https://www.voorhoede.nl/en/blog/static-site-implosion-with-brotli-and-gzip/
- 21 https://www.kickstarter.com/projects/1295587226/air-ink-the-worlds-first-ink-made-out-of-air-pollu
- 22 http://transit.iee.ucsb.edu/research/computing/projects
- 23 https://www.kickstarter.com/projects/1295587226/air-ink-the-worlds-first-ink-made-out-of-air-pollu
- 24 https://www.kickstarter.com/projects/1295587226/air-ink-the-worlds-first-ink-made-out-of-air-pollu
- 25 https://wdrl.info/donate
- 26 https://wdrl.info/costs/