Re: Straw-main XSSModule for CSP

2009-10-20 Thread Adam Barth
On Tue, Oct 20, 2009 at 1:26 PM, Mike Ter Louw wrote: > I'm not sure if hacking at the straw man should occur on the list or on the > wiki.  Please let me know if it should go to the wiki. I've be inclined to discuss feedback on the mailing list where others can see and comment most easily. > Th

Re: Straw-main XSSModule for CSP

2009-10-20 Thread Mike Ter Louw
Adam Barth wrote: I've taken the liberty of sketching out a straw-man XSSModule for CSP on the Mozilla wiki: https://wiki.mozilla.org/Security/CSP/XSSModule I welcome your feedback, Adam Hi Adam, I'm not sure if hacking at the straw man should occur on the list or on the wiki. Please let m

Straw-main XSSModule for CSP

2009-10-17 Thread Adam Barth
Hi dev-security, On Friday, I spoke with Sid, Brandon, and dveditz about dividing the Content Security Policy specification into modules targeted at specific threats. This approach as two main benefits: 1) Different browser vendors can implement CSP incrementally by deploying the most important