e-7723 · Parliament 45
Limit client-side web scripts
AI summary
Petitioners ask the House of Commons to review cybersecurity risks of client-side web scripts used by federally regulated financial institutions and require legislation or binding standards to adopt a script‑minimal, HTML5‑first approach.
AI summaries describe petitioners’ requests and claims. Consult the official record for the full text.
Official petition
Petition to the House of Commons in Parliament assembled Canadians increasingly depend on online banking websites and applications to manage essential financial affairs; Many banking websites rely extensively on client-side web scripts, including third-party scripts, to deliver features that could alternatively be implemented using modern, standards-based HTML5 and browser-native capabilities; Web scripts increase the attack surface of banking platforms and are a recognized vector for data exfiltration, supply-chain compromise, session hijacking, and unauthorized manipulation of web content; HTML5 and related web standards provide native, script-minimal alternatives for many common functions, reducing complexity and exposure to script-based vulnerabilities; and The protection of Canadians’ financial and personal information is a matter of national economic security and public trust. We, the undersigned, citizens and residents of Canada, call upon the House of Commons in Parliament assembled to: 1. Review the cybersecurity risks associated with the use of client-side web scripts on websites and applications operated by federally regulated financial institutions; 1. Review the cybersecurity risks associated with the use of client-side web scripts on websites and applications operated by federally regulated financial institutions; 2. Develop legislation, regulations, or binding standards that prioritize the elimination or strict limitation of non- essential web scripts in favour of secure, standards-based HTML5 and browser-native technologies; and 3. Require federally regulated financial institutions to adopt a “script-minimal by default” approach to digital banking to reduce systemic cyber risk and better protect Canadians.
Government response
No government response is available yet.