Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Roadblocks for Content Security Policy (CSP) Implementation - Developer Challenges and Solutions

OWASP Foundation via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk explores technical and organizational factors that hinder developers from deploying secure Content Security Policies, drawing on a study of developers’ experiences. It discusses ways to address those roadblocks and strategies for developing and hardening a CSP.

Syllabus

Intro
Quick Intro
Cross-Site Scripting (XSS)
Content Security Policy (CSP)
CSP Adoption over time
Script Content Control over time
Developer Survey
Research Questions
Methodology
Drawing Task
Motivations
Roadblock: Complexity
Roadblock: Information Sources
Roadblock: Legacy Code
Roadblocks: Different Teams
Inline Code / 3rd-Parties
3rd-Parties - maintenance effort
Roadblock: Browsers
Problem Solving: Inline Code
Problem Solving Strategies
Problem Solving: Inline Events
Problem Solving: Third Parties
How to start with CSP?
How to harden my CSP?
Conclusion

Taught by

OWASP Foundation

Reviews

Start your review of Roadblocks for Content Security Policy (CSP) Implementation - Developer Challenges and Solutions

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.