IT Chuiko

Facebook Twitter Feed

Mechanism of Content Security Policy in Firefox almost ready

Brandon Sterne, acting head of security at Mozilla, the columns of Security Blog has announced that it has begun the process of implementing the security policy specification content (Content Security Policy, CSP) in Firefox.
How does it work?
Mechanism of Content Security Policy in Firefox almost ready
This mechanism is intended to protect against attacks from cross-site scripting (XSS) and derivatives. It works by distinguishing the original web page content from a modified or introduced from outside. CSP requires that every piece of javascript code was loaded from an external file located on previously confirmed by the server.

All the scripts directly on the page - including links beginning with pattern javascript: HTML attributes and responsible for capturing events - will be ignored. be made only by means of loaded code <script> tags that indicate the system is located on the so-called. white list.

Content Security Policy also allows for the control of other security-related processing of Web page content.
Testers welcome

Anyone who wants to see how the new mechanism of protection, you can download versions of review articles included in the Network by Sterne. Implementation of Content Security Policy is not fully ready, so the testers can notice that some of the points in the specification are not reflected in the actual functions. An example might be there still unfinished HTTP redirects by using the CSP.

In reviewing the possibility of a new security subsystem can be useful Firefox special page demonstrates its capabilities.

Some other stories

Something to say?

blog comments powered by Disqus

Latest Review

Intel introduced Intel Core third generation with vPro technology

Processors Intel Ivy Bridge (Intel Core third generation) were presented some time ago, and now Intel announced the third generation of Intel Core processor technology with vPro, intended for corporate customers and intelligent systems.

Sign Up For Free

Join others: Subscribe for our daily newsletters so you won't miss the latest and greatest stories.

Enter your email address: