Session
CSP is broken, let’s fix it
The CSP standard was supposed to improve the security of websites. But like any standard, it needs to evolve to stay relevant, in the assumptions on how sites are working and in the implementation.
In this talk, we will discuss those gaps, show how the standard can be abused (and is abused), implementation gaps causing it to misbehave in browsers, and bad implementations by website owners who place poor configuration.
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top