4 ms·
I have recently deployed Content Security Policy (CSP) on a website. When I first looked at violation reports, my jaw dropped. The amount of malware (rouge exte
by bluetech 11y ago
I have recently deployed Content Security Policy (CSP) on a website. When I first looked at violation reports, my jaw dropped. The amount of malware (rouge extensions, toolbars, viruses, ...) that is blocked is staggering.
If you really want to help your (clueless) users, never ever serve a login, registration or credit card form without CSP. It really helps - at least until the malware catches on (I already see "Kaspersky Labs" is injecting its domain into the CSP itself).
- tomschlick 11y agoIs there a pre-built tool to capture and manage CSP violation reports? I believe its mainly just a POST request with some JSON right?
- cmdkeen 11y agoYou can use https://report-uri.io/ https://report-uri.io/ to capture violation reports.
- mcpherrinm 11y agohttps://getsentry.com/ https://getsentry.com/ added support for CSP a few months ago, but I haven't tried it out yet. https://github.com/getsentry/sentry/pull/2154 https://github.com/getsentry/sentry/pull/2154
- andy_ppp 11y agoYes, I was about to say this - if you have a secure enough content security policy (and the browser in question supports it properly) it will be impossible for an attacker to execute their inserted Javascript (which to be able to do this anyway is also a security vulnerability). But yes, the best plan is to have HTTPS everywhere, something that looks a lot closer than it once did! Thanks NSA!
- briandh 11y ago> if you have a secure enough content security policy (and the browser in question supports it properly) it will be impossible for an attacker to execute their inserted Javascript I don't follow your reasoning. Why wouldn't an MITM attacker modifying an HTTP response body to insert rogue Javascript also be able to modify the response headers to strip or alter the Content Security Policy?
- andy_ppp 11y agoGood point about MITM attacks; I assumed that we were talking about cross site scripting (XSS), but I suppose you are right. I still am willing to bet that SSL is not impossible to MITM. Someone will manage to find a flaw in such a complex system.
- Ntrails 11y ago>rouge extensions Man, World Of Warcraft flashbacks can be intense sometimes...
- pmarreck 11y agoLEVEL 70 ROUGE TWINK GUIDE CLICK HERE
- bzbarsky 11y agoNote that per the CSP spec, browser extensions should NOT be affected by CSP. The fact that they are in browsers is technically a bug, caused by the fact that once you've injected stuff into a page browsers don't so much track where it came from... This does mean that currently CSP can stop various malware-ish extensions, but also that it stops legitimate ones (e.g. say an extension wants to apply a certain font that the user finds more readable to the entire page). It's a tough tradeoff.