Home
Subscriptions
Explore
Dashboard
Newsletter
New post
Search...
Ctrl
+
K
alp1n3.eth
Sign in
View all posts
Posts tagged with
content-security-policy
(1)
Collects
0
Posts
18
Search...
Ctrl
+
K
alp1n3.eth
Sign in
View all posts
Posts tagged with
content-security-policy
(1)
Posts
18
Collects
0
Content Security Policy - alp1n3.eth
Subscribers
<100
Subscribers
<100
Subscribe
Subscribe
Subscribe
Subscribe
alp1n3.eth
Nov 5
Why is the Content-Security-Policy Header so Important?
TL;DR: Defense-in-depth. There's a reason a lot of these protections exist in the first place. Please use them.I know most places will auto-categorize a missing Content-Security-Policy (CSP) as an informational severity finding until cross-site scripting (XSS) is found, as there isn't technically a vulnerability (yet). I'm a huge fan of defense-in-depth, so while I support a default low rating, I know it'll never happen to the current specifications and rating schemes. Just keep in mind that ...
alp1n3.eth
Nov 5
Why is the Content-Security-Policy Header so Important?
TL;DR: Defense-in-depth. There's a reason a lot of these protections exist in the first place. Please use them.I know most places will auto-categorize a missing Content-Security-Policy (CSP) as an informational severity finding until cross-site scripting (XSS) is found, as there isn't technically a vulnerability (yet). I'm a huge fan of defense-in-depth, so while I support a default low rating, I know it'll never happen to the current specifications and rating schemes. Just keep in mind that ...
alp1n3.eth
Ruminating on Web3, Security, and Privacy.
alp1n3.eth
Ruminating on Web3, Security, and Privacy.
Written by
alp1n3.eth 🌲
Written by
alp1n3.eth 🌲