- From: Mike West <mkwst@google.com>
- Date: Wed, 12 Feb 2014 15:43:12 +0100
- To: Egor Homakov <homakov@gmail.com>
- Cc: "public-webappsec@w3.org" <public-webappsec@w3.org>
Received on Wednesday, 12 February 2014 14:44:04 UTC
On Wed, Feb 12, 2014 at 11:55 AM, Egor Homakov <homakov@gmail.com> wrote: > Author of the article here :) I believe killing paths is killing point of > CSP, furthermore, I'd like to have ?query whitelisted too! > Really? Neither GitHub nor Facebook use paths in their policies today. I don't actually know of any service making use of the feature. I'd be happy to be wrong about that if someone has examples. > We should patch the whole right where it happens - leakage. We should make > it impossible to detect whether CSP has blocked a resource. Fake > width/height of images, fire onload events, just like nothing happened. > As noted in the last email, I don't honestly think this is possible. -mike
Received on Wednesday, 12 February 2014 14:44:04 UTC