Exploring Information Security - Exploring Information Security podcast

How to Implement a Content Security Policy (CSP)

0:00
45:25
Recuar 15 segundos
Avançar 15 segundos
Summary: In this episode of the Exploring Information Security podcast, host Timothy De Block sits down with Jason Gillam, long-time developer turned penetration tester and partner at Secure Ideas. The two dive into the real-world value of Content Security Policy (CSP) and why it remains one of the most underutilized tools in web application defense. Jason shares insights from his upcoming talk at ShowMeCon 2025, including surprising statistics from his analysis of over 750,000 domains, where he found that most CSPs are either missing or misconfigured. He breaks down how CSP works, its role in protecting against injection attacks, and strategies for implementing it properly using nonces, hashes, and report-only modes. They also discuss: The challenges of educating developers on CSP CSP vs. WAF and where each fits in the security stack How AI and CI/CD can support secure CSP deployment The importance of building security into code rather than bolting it on later Whether you're a developer, security professional, or somewhere in between, this episode offers practical and actionable advice on improving your web application security posture. Mentioned Resources: OWASP CSP Cheat Sheet Google CSP Evaluator Use the promo code “ExploringSec” to get $50 off your registration

Mais episódios de "Exploring Information Security - Exploring Information Security"