In this talk at Code Camp Auckland, Kirk discussed the latest protections that have been added to web browsers to combat the common threats to your web applications.
He covered Content Security Policy (CSP), HTTP Strict Transport Security (HSTS) and the X-Frame-Options headers, as well as discussing how to safely host user-generated files for download.
View the slides here: CC2011-KirkJackson.pdf (6mb)
Get the latest web and dev security information from the Hack-Ed team.
Showing posts with label HSTS. Show all posts
Showing posts with label HSTS. Show all posts
Sunday, August 28, 2011
Thursday, July 14, 2011
WDCNZ - Web Security: Get Ahead(er)
Kirk Jackson presented at the inaugural WDCNZ conference in Wellington.
This talk covered new browser support for Content Security Policy and HTTP Strict Transport Security headers, as well as miscellaneous other web security techniques to protect your applications from XSS, man-in-the-middle and other attacks.
Download the slides: KirkJackson-WDCNZ-GetAHeader-online.pdf (1.3mb)
This talk covered new browser support for Content Security Policy and HTTP Strict Transport Security headers, as well as miscellaneous other web security techniques to protect your applications from XSS, man-in-the-middle and other attacks.
Download the slides: KirkJackson-WDCNZ-GetAHeader-online.pdf (1.3mb)
Subscribe to:
Posts (Atom)