Hacker News new | past | comments | ask | show | jobs | submit login

The linked W3C mailing list[1] provides some interesting discussion, as well as a blog post from Jan outlining this attack[2].

The conclusion: security benefits of CSP outweigh cons.

[1] http://lists.w3.org/Archives/Public/public-webappsec/2014Feb...

[2] http://homakov.blogspot.de/2014/01/using-content-security-po...




Thanks. Especially the homakov post is enlightening, as it explains that removing the report-uri feature is not even enough to make this exploit impossible, as the onload/onerror events also signal success or failure.

Is there anything good that report-uri is used for that is more important than removing this exploit possibility?


Report URIs are pretty important for deploying CSP on an existing site. Without it, you'd have to risk breaking the experience for a lot of users (because it's hard to nail the policy on the first try) and you'd never get any logs explaining what was blocked.




The deadline for YC's W25 batch is 8pm PT tonight. Go for it!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: