Welcome!

Containers Expo Blog Authors: Rich DeFabritus, Elizabeth White, Yeshim Deniz, Mehdi Daoudi, PagerDuty Blog

Related Topics: Cloud Security, Mobile IoT, Microservices Expo, ColdFusion, IBM Cloud, Weblogic, Linux Containers, Open Source Cloud, Containers Expo Blog, Machine Learning , Agile Computing, Release Management , Recurring Revenue, Log Management, @CloudExpo, Apache, Government Cloud

Cloud Security: Interview

Bulletproofing the WebSocket Wire Protocol

There's been a flurry of discussion this week among Internet & Web standards experts about the WebSocket communications protocol

Web Security Journal: There's been a flurry of discussion this week among Internet and Web standards heavy-hitters around WebSocket, the new communications protocol supported in Chrome 4 and Safari 5. What was the main issue? Is there some kind of fundamental security vulnerability with the WebSocket (WS) protocol?

John Fallows: When surfing the Web, our browsers may communicate with Web servers via HTTP proxies that deliver many benefits, such as providing previously cached Web content more efficiently than repeatedly contacting the target server. These proxies may be either explicitly configured at the browser or they may form part of the general network topology to intercept the communication path implicitly. Securely encrypted Web communication cannot be intercepted by such proxies.

Members of the Hypertext Bidirectional (HyBi) IETF Working Group recently completed a study to test the vulnerabilities of these implicit, intercepting HTTP proxies. The study found that the raw socket capabilities of Flash and Java could be used to mount an attack on these intercepting HTTP proxies, such that an attacker might be able to influence the contents of the cache and change the behavior of specific sites for users accessing those sites through the same intercepting HTTP proxy.

The results showed that of the 47,338 intercepting HTTP proxies tested with the unencrypted WebSocket handshake alone, 0.37% and 0.017% were found vulnerable for the two specific attacks described in the study.

Web Security Journal: If the flaw lies not in WebSockets, but in some particular type of proxies, why are commentators inclining towards discussing WebSockets and only WebSockets?

Fallows: If all intercepting HTTP proxies correctly implemented the HTTP standard, then the 101 Switching Protocols response used by WebSocket handshake would be both sufficient and elegant.

Even though these intercepting HTTP proxies vulnerabilities have been enabled by Flash and Java for a long time, they were reported in the study as part of the IETF working group design process for the WebSocket wire protocol, therefore commentators have been inclined to comment specifically about the WebSockets portion of this result.

In the short term, browser providers have elected to temporarily withdraw the JavaScript WebSocket API from deployed browser implementations until they and others in the IETF working group reach agreement on how to bulletproof the WebSocket wire protocol to handle even buggy implementations of intercepting HTTP proxies. There are already proposals in place so I anticipate a timely resolution early next year.

Web Security Journal: The tests that spurred Mozilla and Opera to disable WebSockets as the default were done with Java and Flash clients. That means presumably that this issue has been around long before WebSockets? Why hasn't it been caught and dealt with before?

Fallows: The WebSocket wire protocol design effort has brought together a huge community of experts to deliver this functionality such that it can be deployed on a global scale, which necessitates such experiments to validate the standards compliance of deployed HTTP proxy infrastructure.

It will be interesting to see how Adobe and Oracle respond to address the vulnerabilities enabled by raw socket access in Flash and Java. Perhaps this will encourage them to adopt WebSockets as a native part of their platform, and have a more restrictive policy on raw socket access for Web deployments of their plug-in technologies.

Web Security Journal: What's the exact current status, then? The protocol is being standardized by the IETF as we speak, but what about the WebSocket API overall? What's its status vis-a-vis the W3C?

Fallows: The W3C JavaScript WebSocket API remains unchanged in its definition. However, browser providers await resolution of the WebSocket wire protocol at the IETF before deploying an implementation.

Web Security Journal: So is it accurate to describe WebSockets - still - as an early stage specification at the moment?

Fallows: The WebSocket wire protocol is currently in the IETF Internet Draft stage, and there is no shortage of support or dedication in the Hypertext Bidirectional Working Group to reach completion in a timely manner.

Web Security Journal: You mentioned earlier that there's no real barrier to improving the WebSocket protocol the moment it is bulletproofed to withstand broken infrastructure, since such an improvement can simply be included in the latest update of whatever browser a user is using. But the creator of JavaScript, Brendan Eich, has warned that we might end up with what he calls "version skew" because users won't necessarily switch browsers just to get the latest version of WS. He asks, rhetorically: "Are we going to synchronize Firefox's release cycle with Chrome's? Is Opera? Is Safari?" Isn't that a valid concern?

Fallows: Web browsers have always innovated beyond the standards, in part to differentiate themselves and in part to drive the standards forward with the benefit of real-world experience. WebSocket is a good example of that, having evolved beyond both Ajax and Comet, as well as raw socket communication provided by plug-ins. If we are careful to provide a stable and extensible WebSocket base, as was achieved with HTTP, then I would fully expect to see browsers implementing custom enhancements to that base, and it will be the responsibility of WebSocket gateway providers to support for those enhancements.

Web Security Journal: Mozilla, despite disabling it as the default in Firefox 4, says it is "excited" by WebSockets. Why is such a major browser player "excited" - what is it about WebSockets that gets a major Internet force like the Mozilla Foundation to be so upbeat about its potential?

Fallows: WebSockets, and HTML5 in general, represent a leap forward for the Web application platform and it is certainly an "exciting" time for all of us using the Web today. For decades we have seen the evolution of Web applications with gradually increasing interactivity getting closer and closer to their desktop installed counterparts. WebSockets allows us to add the final piece of that puzzle, providing desktop class TCP network connectivity while traversing the HTTP-constrained infrastructure of the Web. A new breed of applications can now be built using WebSocket with a fraction of the server-side infrastructure costs, optimized network bandwidth utilization and more immediate delivery of time-sensitive information.

Web Security Journal: And where does the WebSocket protocol sit in terms of HTML5 specification?

The WebSocket wire protocol is governed by the IETF who manage many of the world's protocols like HTTP, FTP, SMTP, and others.

The W3C standards body maintains the both HTML5 specification and the WebSocket API specification which defines how JavaScript applications can leverage WebSocket functionality.

Browser providers depend on both standards to fully deliver WebSocket functionality.

Web Security Journal: Adam Barth, whose paper on a possible exploit of transparent proxies sparked this latest discussion, has also described a handshake for the WebSocket protocol that resists cross-protocol attacks. Is that the direction the IETF will go do you think?

Fallows: Ultimately there are a few ways to proceed that balance HTTP compatibility with strategies to overcome non-compliant HTTP proxies. Given that the same study demonstrated no successful attacks on Adam's proposed enhancement to the WebSocket handshake, it seems to be a very strong candidate as we move forward.

Web Security Journal: Can't a WebSocket connection simply be encrypted? Wouldn't that render this whole issue moot - or is that too simplistic?

Fallows: The attacks identified by Adam Barth's paper would not be possible using an encrypted WebSocket connection because the HTTP proxy would not be able to see the encrypted wire traffic and could therefore not be confused into triggering the buggy behavior. If the browser providers restricted encrypted-only access to WebSockets then this issue could be avoided.

Web Security Journal: So from a Kaazing perspective, then, is it your intention to propagate the world with WebSockets and then go to sleep with the feeling of a job well done, or is the propagation of WS gateways the means to some other kind of business goal?

Fallows: At Kaazing, we believe that WebSockets is the beginning of a new future for Web applications as we move from the disconnected world of yesterday to the always connected, always up-to-date world we live in today. We understand that while WebSockets provide the foundation of that new beginning, the majority of the new capabilities lie in how you use WebSocket to support higher-level protocols that make it straightforward to solve technical challenges that would have taken significantly more effort to achieve otherwise.

Our goals are to help to world transition to this new standard easily and efficiently, and continue to deliver solutions that eliminate the unnecessary architectural complexity found in many Web applications today.

Web Security Journal: And is anybody yet finding that they can make more money, or spend less, because of Kaazing's offerings? Are there real-world implementations at all?

Fallows: We have customers in the Financial Services, Sports Betting, and Online Auctions markets that have used our technology to reduce infrastructure costs, reduce time-to-market, improve end-user experience and drive their revenues more efficiently.

Web Security Journal: What, in your view, is the best way of channeling developers' interest in experimenting with what a WebSocket gateway can do for their architecture? How can someone who is not yet au fait with the technbology most easily play catch-up?

Fallows: The WebSocket.org site is dedicated to explaining the various aspects of WebSocket technology and would be a useful starting point for those wishing to read up. It contains links to the relevant WebSocket API and wire protocol specifications, including a discussion of the many benefits of WebSockets.

A developer download of Kaazing WebSocket Gateway is also freely available from kaazing.com. This delivers emulation of the standard WebSocket API for all browsers. So in the interim until browser providers re-enable WebSockets, developers can still experiment with the same WebSocket APIs in both current and older browsers that will prepare them for the future of Web communication.

More Stories By Security News Desk

SYS-CON's Security News desk trawls the world of security for news of software, hardware, products, and services that seems likely to be of interest to infosec professionals and summarizes them for easy assimilation by busy IT managers and staff.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
In his keynote at @ThingsExpo, Chris Matthieu, Director of IoT Engineering at Citrix and co-founder and CTO of Octoblu, focused on building an IoT platform and company. He provided a behind-the-scenes look at Octoblu’s platform, business, and pivots along the way (including the Citrix acquisition of Octoblu).
In his keynote at 18th Cloud Expo, Andrew Keys, Co-Founder of ConsenSys Enterprise, provided an overview of the evolution of the Internet and the Database and the future of their combination – the Blockchain. Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settle...
SYS-CON Events announced today that SD Times | BZ Media has been named “Media Sponsor” of SYS-CON's 20th International Cloud Expo, which will take place on June 6–8, 2017, at the Javits Center in New York City, NY. BZ Media LLC is a high-tech media company that produces technical conferences and expositions, and publishes a magazine, newsletters and websites in the software development, SharePoint, mobile development and commercial UAV markets.
“We're a global managed hosting provider. Our core customer set is a U.S.-based customer that is looking to go global,” explained Adam Rogers, Managing Director at ANEXIA, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
In today's uber-connected, consumer-centric, cloud-enabled, insights-driven, multi-device, global world, the focus of solutions has shifted from the product that is sold to the person who is buying the product or service. Enterprises have rebranded their business around the consumers of their products. The buyer is the person and the focus is not on the offering. The person is connected through multiple devices, wearables, at home, on the road, and in multiple locations, sometimes simultaneously...
China Unicom exhibit at the 19th International Cloud Expo, which took place at the Santa Clara Convention Center in Santa Clara, CA, in November 2016. China United Network Communications Group Co. Ltd ("China Unicom") was officially established in 2009 on the basis of the merger of former China Netcom and former China Unicom. China Unicom mainly operates a full range of telecommunications services including mobile broadband (GSM, WCDMA, LTE FDD, TD-LTE), fixed-line broadband, ICT, data communica...
As businesses adopt functionalities in cloud computing, it’s imperative that IT operations consistently ensure cloud systems work correctly – all of the time, and to their best capabilities. In his session at @BigDataExpo, Bernd Harzog, CEO and founder of OpsDataStore, will present an industry answer to the common question, “Are you running IT operations as efficiently and as cost effectively as you need to?” He will expound on the industry issues he frequently came up against as an analyst, and...
WebRTC is about the data channel as much as about video and audio conferencing. However, basically all commercial WebRTC applications have been built with a focus on audio and video. The handling of “data” has been limited to text chat and file download – all other data sharing seems to end with screensharing. What is holding back a more intensive use of peer-to-peer data? In her session at @ThingsExpo, Dr Silvia Pfeiffer, WebRTC Applications Team Lead at National ICT Australia, looked at differ...
With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo 2016 in New York. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be! Internet of @ThingsExpo, taking place June 6-8, 2017, at the Javits Center in New York City, New York, is co-located with 20th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry p...
IoT offers a value of almost $4 trillion to the manufacturing industry through platforms that can improve margins, optimize operations & drive high performance work teams. By using IoT technologies as a foundation, manufacturing customers are integrating worker safety with manufacturing systems, driving deep collaboration and utilizing analytics to exponentially increased per-unit margins. However, as Benoit Lheureux, the VP for Research at Gartner points out, “IoT project implementers often un...
SYS-CON Events announced today that Technologic Systems Inc., an embedded systems solutions company, will exhibit at SYS-CON's @ThingsExpo, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Technologic Systems is an embedded systems company with headquarters in Fountain Hills, Arizona. They have been in business for 32 years, helping more than 8,000 OEM customers and building over a hundred COTS products that have never been discontinued. Technologic Systems’ pr...
SYS-CON Events announced today that IoT Now has been named “Media Sponsor” of SYS-CON's 20th International Cloud Expo, which will take place on June 6–8, 2017, at the Javits Center in New York City, NY. IoT Now explores the evolving opportunities and challenges facing CSPs, and it passes on some lessons learned from those who have taken the first steps in next-gen IoT services.
SYS-CON Events announced today that WineSOFT will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Based in Seoul and Irvine, WineSOFT is an innovative software house focusing on internet infrastructure solutions. The venture started as a bootstrap start-up in 2010 by focusing on making the internet faster and more powerful. WineSOFT’s knowledge is based on the expertise of TCP/IP, VPN, SSL, peer-to-peer, mob...
SYS-CON Events announced today that delaPlex will exhibit at SYS-CON's @CloudExpo, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. delaPlex pioneered Software Development as a Service (SDaaS), which provides scalable resources to build, test, and deploy software. It’s a fast and more reliable way to develop a new product or expand your in-house team.
You think you know what’s in your data. But do you? Most organizations are now aware of the business intelligence represented by their data. Data science stands to take this to a level you never thought of – literally. The techniques of data science, when used with the capabilities of Big Data technologies, can make connections you had not yet imagined, helping you discover new insights and ask new questions of your data. In his session at @ThingsExpo, Sarbjit Sarkaria, data science team lead ...
The Internet of Things can drive efficiency for airlines and airports. In their session at @ThingsExpo, Shyam Varan Nath, Principal Architect with GE, and Sudip Majumder, senior director of development at Oracle, discussed the technical details of the connected airline baggage and related social media solutions. These IoT applications will enhance travelers' journey experience and drive efficiency for the airlines and the airports.
The security needs of IoT environments require a strong, proven approach to maintain security, trust and privacy in their ecosystem. Assurance and protection of device identity, secure data encryption and authentication are the key security challenges organizations are trying to address when integrating IoT devices. This holds true for IoT applications in a wide range of industries, for example, healthcare, consumer devices, and manufacturing. In his session at @ThingsExpo, Lancen LaChance, vic...
With billions of sensors deployed worldwide, the amount of machine-generated data will soon exceed what our networks can handle. But consumers and businesses will expect seamless experiences and real-time responsiveness. What does this mean for IoT devices and the infrastructure that supports them? More of the data will need to be handled at - or closer to - the devices themselves.
SYS-CON Events announced today that Dataloop.IO, an innovator in cloud IT-monitoring whose products help organizations save time and money, has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Dataloop.IO is an emerging software company on the cutting edge of major IT-infrastructure trends including cloud computing and microservices. The company, founded in the UK but now based in San Fran...
In his session at @ThingsExpo, Sudarshan Krishnamurthi, a Senior Manager, Business Strategy, at Cisco Systems, will discuss how IT and operational technology (OT) work together, as opposed to being in separate siloes as once was traditional. Attendees will learn how to fully leverage the power of IoT in their organization by bringing the two sides together and bridging the communication gap. He will also look at what good leadership must entail in order to accomplish this, and how IT managers ca...