alp1n3.eth
alp1n3.eth
Toggle theme
Subscribers
<100
alp1n3.eth
Ruminating on Web3, Security, and Privacy.
Links
alp1n3.eth
View all posts
Posts tagged with
content-security-policy
(1)
Written by
alp1n3.eth 🌲
Subscribe
Subscribe
Posts
18
Collects
0
Why is the Content-Security-Policy Header so Important?
alp1n3.eth
Nov 5
TL;DR: Defense-in-depth. There's a reason a lot of these protections exist in the first place. Please use them.I know most places will auto-categorize a missing Content-Security-Policy (CSP) as an informational severity finding until cross-site scripting (XSS) is found, as there isn't technically a vulnerability (yet). I'm a huge fan of defense-in-depth, so while I support a default low rating, I know it'll never happen to the current specifications and rating schemes. Just keep in mind that ...
Collect