Devdatta Akhawe: How I learnt to play in the (CSP) Sandbox
Автор: LocoMocoSec: Hawaii Product Security Conference
Загружено: 2018-04-27
Просмотров: 963
Описание: The typical way to isolate untrusted components on the web is to run them in an isolated domain. While very secure, "untrustedsite.com" is not the best place to host a lot of content like help center, forums, marketing pages. It looks bad and has a bunch of administrative overhead. Instead, an alternative is to use the CSP sandbox directive to isolate untrusted components in the "null" origin but still serve them from your main site. This is a lot easier to deploy and provides a powerful mitigation. This talk will cover how we deployed a CMS on www.dropbox.com without increasing our XSS risk; some interesting corner cases to think about; and a discussion on upcoming primitives like Suborigins that will make all of this a lot easier.
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: