XSS is Dead - Browser Security Features that Eliminate Bug Classes
Build GenAI Apps from Scratch — UCSB PaCE Certificate Program
The Private Equity Associate Certification
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Explore how modern browser security features can eliminate entire classes of vulnerabilities in this 22-minute conference talk. Learn why traditional application security approaches of patching and bug bounties create endless cycles, and discover how browser-native protections like Content Security Policy v3, Trusted Types, and Sec-Fetch-Metadata headers can prevent XSS, CSRF, clickjacking, and cross-origin attacks at the source. Examine real-world case studies from organizations successfully implementing these browser security mechanisms, and gain practical guidance on integrating, automating, and enforcing secure defaults in your applications. Understand how to shift from reactive security patching to proactive vulnerability prevention through leveraging built-in browser capabilities.
Syllabus
- Date/Time: Tuesday, 14:00–14:20
Taught by
BSidesLV