29 March 2011

CSP Spring Update

In November I discussed Content Security Policy (CSP), a new method to help mitigate Cross Site Scripting (XSS) vulnerabilities.

Mallard ducks on the river's edge at Corbridge in Northumberland

Earlier this month Content Security Policy was formally submitted to the World Wide Web Consortium (W3C) as an unofficial draft. This is a very early, but encouraging, step on its way to becoming more formally accepted.

Last week Firefox 4, which supports CSP, was officially launched by Mozilla Foundation. There is a good summary of all the security features on the SANS web site.

Posted on: 29 March 2011 at 07:50 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
CSP Spring Update
http://www.clerkendweller.com/2011/3/29/CSP-Spring-Update
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2011/3/29/CSP-Spring-Update
Requested by 38.107.179.222 on Thursday, 17 May 2012 at 22:53 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2011-2012 clerkendweller.com