On Thu, 30 Jul 2009 19:51:45 +0200, Daniel Veditz <[email protected]> wrote:
> Ian Hickson wrote:
>>> If a large site such as Twitter were to implement it,
>>> that's millions of users protected that otherwise wouldn't be.
>>
>> Assuming they got it right.
>
> If they don't some researcher gets an easy conference talk out of
> bypassing the restrictions and poking fun at them, and then it gets
> fixed. The sites most likely to use and benefit from CSP are the ones
> most likely to be closely watched.

I seriously doubt that. I was at a conference in Portugal where a major ISP got 
pointed out the enormous amounts of holes they had which makes me think that 
given the severity of the problem (that and Rasmus Lerdorf indicating this was 
nothing new) it needs a rather simple solution because authors will not get it. 
They are not informed about all the various attacks that can happen on sites. 
Not at all. And this is not surprising given the vast complexity of the Web 
platform.

(Tne conference was a few months ago.)


-- 
Anne van Kesteren
http://annevankesteren.nl/

Reply via email to