Stories
Slash Boxes
Comments
typodupeerror delete not in

+-   Firefox Standard Will Combat Cross-Site-Scripting-> on Monday June 29, @03:27PM Al

Submitted by Al on Monday June 29, @03:27PM
mozilla
Al writes "The Mozilla foundation is to adopt a new standard to help web site's prevent cross site scripting (XSS) attacks. The standard, called Content Security Policy (CSP), will let a website specify what Internet domains are allowed to host the scripts that run on its pages. This breaks with Web browsers' tradition of treating all scripts the same way by requiring that websites put their scripts in separate files and explicitly state which domains are allowed to run the scripts. The Mozilla Foundation selected the implementation because it allows sites to choose whether to adopt the restrictions. "The severity of the XSS problem in the wild and the cost of implementing CSP as a mitigation are open to interpretation by individual sites," Brandon Sterne, security program manager for Mozilla, wrote on Mozilla Security Blog. "If the cost versus benefit doesn't make sense for some site, they're free to keep doing business as usual."
Link to Original Source
submission

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
Learn to pause -- or nothing worthwhile can catch up to you.