Get a Pentest and security assessment of your IT network.

News

Defense-in-Depth Techniques for Modern Web Applications and Googles Journey with CSP

In this presentation, we show promising new defense-in-depth techniques to protect modern web applications from old and new classes of bugs. Suborigins to have finer-grained control over origin boundaries, Site Isolation and XSDB against Spectre and Meltdown attacks, and last but not least Origin and Feature Policy. We explain new features of the upcoming CSP 3 specification like unsafe-hashed-attributes and give an overview of how we were able to enforce CSP as a strong mitigation against cross-site scripting on over 50% of production web traffic.”]

Source: https://conference.hitb.org/hitbsecconf2018ams/sessions/defense-in-depth-techniques-for-modern-web-applications-and-googles-journey-with-csp/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Take note, next week update Adobe Reader and Acrobat to fix critical flaws

News

Linux bug leaves 1.4 billion Android users vulnerable to hijacking attacks