Collected research
CSP Is Dead, Long Live CSP!
CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security Policy
Internet-scale measurement of Content Security Policy across 1.6 million hosts and 26,011 distinct policies finds 94.72 percent of policies bypassable, chiefly because whitelisted script hosts serve endpoints that hand back attacker-controlled script. Proposes the strict-dynamic keyword so nonce-based policies can replace host whitelists.
Record
- Document
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security Policy
- Researcher
- Lukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies and Artur Janc
- Published by
- research.google
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Lukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies and Artur Janc, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .