Mozilla Content Security Policy
Posted: Tue Jun 30, 2009 6:32 pm
It looks like Mozilla is actively working towards putting some XSS, CSRF, and click-jacking protections into their browsers. Their Content Security Policy seems reasonably detailed and is targeted to incorporate at least some of the protections that NoScript offers. Since CSP is optional and can be implemented via HTML meta tags that can be spoofed on a compromised site, I don't see NoScript going away any time soon. However I have to ask: Giorgio, are you involved with CSP in any official capacity? And do you think CSP is going in the right direction or is it simply a misstep that will further cloud the already foggy browser security landscape?
Thanks,
-Foam
Thanks,
-Foam