Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> CSP is one of the worst pieces of Web security infrastructure

I disagree. Like many things, it's a trade-off, in this case between configurability and extensibility for those who know what they're doing and security for those who don't. In the grand scheme of things, it seems pretty reasonable.



That doesn't make sense. CSP is opt-in.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: