
How to Implement a Content Security Policy (CSP)
0:00
45:25
Summary:
In this episode of the Exploring Information Security podcast, host Timothy De Block sits down with Jason Gillam, long-time developer turned penetration tester and partner at Secure Ideas. The two dive into the real-world value of Content Security Policy (CSP) and why it remains one of the most underutilized tools in web application defense.
Jason shares insights from his upcoming talk at ShowMeCon 2025, including surprising statistics from his analysis of over 750,000 domains, where he found that most CSPs are either missing or misconfigured. He breaks down how CSP works, its role in protecting against injection attacks, and strategies for implementing it properly using nonces, hashes, and report-only modes.
They also discuss:
The challenges of educating developers on CSP
CSP vs. WAF and where each fits in the security stack
How AI and CI/CD can support secure CSP deployment
The importance of building security into code rather than bolting it on later
Whether you're a developer, security professional, or somewhere in between, this episode offers practical and actionable advice on improving your web application security posture.
Mentioned Resources:
OWASP CSP Cheat Sheet
Google CSP Evaluator
Use the promo code “ExploringSec” to get $50 off your registration
Mais episódios de "Exploring Information Security - Exploring Information Security"
Não percas um episódio de “Exploring Information Security - Exploring Information Security” e subscrevê-lo na aplicação GetPodcast.