CSP Spring Update
In November I discussed Content Security Policy (CSP), a new method to help mitigate Cross Site Scripting (XSS) vulnerabilities.
Earlier this month Content Security Policy was formally submitted to the World Wide Web Consortium (W3C) as an unofficial draft. This is a very early, but encouraging, step on its way to becoming more formally accepted.
Last week Firefox 4, which supports CSP, was officially launched by Mozilla Foundation. There is a good summary of all the security features on the SANS web site.
Posted on: 29 March 2011 at 07:50 hrs

Comments are filtered automatically and should appear shortly after they been checked.