$less ~/slides/csp-a-successful-mess
// deck 06 · LocoMocoSec
Content Security Policy
A successful mess between hardening and mitigation
1 / 56
skip thumbnails
// key slides
// what you take away
- A strict CSP blocked 60 to 80% of externally reported XSS at Google in 2018.
- Automated tools bypass more than 95% of the web's allowlist CSPs.
- Start with nonce plus 'strict-dynamic'; move to nonce-only once you control all JS.















































































































