LavaMoat / LavaDome

Secure DOM trees isolation and encapsulation leveraging ShadowDOM
https://lavamoat.github.io/LavaDome/packages/core/demo/
MIT License
16 stars 3 forks source link

Defend against font-face side channeling attack, and refactor #17

Closed weizman closed 6 months ago

weizman commented 6 months ago

16 fix by adding all chars invisibly to the LavaDome shadow, so that such font-face lookup just finds all possible chars, leaving attack useless.

Also, refactor code base