Security/CSP/RelevantLinks
From MozillaWiki
Our Postings
30 June 2009: CSP With or Without Meta
19 June 2009: Shutting Down XSS with Content Security Policy
Select Articles talking about CSP
3-October-09
- says we're shepherding it through W3C...
- is a bit skeptical, considers adoption of CSP a longshot
1-July-09
29-June-09
25-June-09
24-June-09
23-June-09
- suggests disregarding meta tags when HTTP header is present
- presents possible attack using E4X
22-June-09
- Calls for support of X-FRAME-OPTIONS
Discussion Threads
mozilla.dev.security: "content security policy" "csp"
Similar to CSP
"HTTP Immigration Control" (July 2008 Tech Report) : http://news.knownspace.org/cgi-bin/techreports/TRNNN.cgi?trnum=TR669
"Application Boundaries Enforcer (ABE)" (December 2008 Blog Post) : http://hackademix.net/2008/12/20/introducing-abe/