Главная
Study mode:
on
1
Intro
2
Quick Intro
3
Cross-Site Scripting (XSS)
4
Content Security Policy (CSP)
5
CSP Adoption over time
6
Script Content Control over time
7
Developer Survey
8
Research Questions
9
Methodology
10
Drawing Task
11
Motivations
12
Roadblock: Complexity
13
Roadblock: Information Sources
14
Roadblock: Legacy Code
15
Roadblocks: Different Teams
16
Inline Code / 3rd-Parties
17
3rd-Parties - maintenance effort
18
Roadblock: Browsers
19
Problem Solving: Inline Code
20
Problem Solving Strategies
21
Problem Solving: Inline Events
22
Problem Solving: Third Parties
23
How to start with CSP?
24
How to harden my CSP?
25
Conclusion
Description:
Explore the challenges and solutions surrounding Content Security Policy (CSP) implementation in this informative conference talk. Delve into the complexities of CSP as a crucial web security mechanism, examining its effectiveness in mitigating Cross-Site Scripting (XSS) attacks. Discover why many real-world CSP deployments are easily bypassable and understand the roadblocks developers face when implementing secure policies. Learn about the various factors hindering CSP adoption, including framework and browser support, plugins, error reports, and information sources. Gain insights from a developer survey and research findings on CSP deployment challenges. Explore actionable strategies for developing secure CSPs, addressing issues like inline code, third-party integrations, and legacy code. Understand how to start implementing CSP and methods for hardening existing policies. Engage with practical problem-solving approaches and best practices to enhance web application security through effective CSP implementation. Read more

Roadblocks for Content Security Policy (CSP) Implementation - Developer Challenges and Solutions

OWASP Foundation
Add to list