alp1n3.eth

alp1n3.eth

alp1n3.eth

View all posts
Posts tagged with
csp(1)
Discover card cover image
Why is the Content-Security-Policy Header so Important?
Blog iconalp1n3.eth
Nov 5
TL;DR: Defense-in-depth. There's a reason a lot of these protections exist in the first place. Please use them.I know most places will auto-categorize a missing Content-Security-Policy (CSP) as an informational severity finding until cross-site scripting (XSS) is found, as there isn't technically a vulnerability (yet). I'm a huge fan of defense-in-depth, so while I support a default low rating, I know it'll never happen to the current specifications and rating schemes. Just keep in mind that ...
alp1n3.eth

alp1n3.eth

Written by
alp1n3.eth 🌲alp1n3.eth 🌲

Ruminating on Web3, Security, and Privacy.

Subscribers<100
Posts18
Collects0

ÂŠī¸ 2025 Paragraph Technologies Inc

Privacy policyTerms of useDiscover great writing

alp1n3.eth
View all posts
Posts tagged with
csp(1)
Discover card cover image
Why is the Content-Security-Policy Header so Important?
Blog iconalp1n3.eth
Nov 5
TL;DR: Defense-in-depth. There's a reason a lot of these protections exist in the first place. Please use them.I know most places will auto-categorize a missing Content-Security-Policy (CSP) as an informational severity finding until cross-site scripting (XSS) is found, as there isn't technically a vulnerability (yet). I'm a huge fan of defense-in-depth, so while I support a default low rating, I know it'll never happen to the current specifications and rating schemes. Just keep in mind that ...

Blog logo
Subscribe to alp1n3.eth

Stay updated by getting the latest posts delivered directly to your inbox.

Read it first