Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Neil Matatall — Content Security Policy

43 min4 augusti 2020

Om avsnittet

Neil Matatall is a product security engineer at GitHub. He focuses on designing and engineering user experiences solutions related to authentication and account recovery. Working remotely from Hawaii, Neil is a strong believer in the future of remote work. Neil joins us for a deep-dive into Content Security Policy. We explore what it is, the purpose, and why it's so difficult to implement. Neil Madhatal is a product security engineer at GitHub. Neil joins us for a deep dive into content security policy. We hope you enjoy this conversation with— Neil Madhatal. Are you trying to build a security champions program? Everyone is these days.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Neil Madhatal is a product security engineer at GitHub.
Learn more about Security Journey

Connect with Neil Matatall:
github/secure_headers
Content-Security-Policy (MDN)

Mentioned in this episode:
github/secure_headers
Content-Security-Policy (MDN)
Scott Helme
Troy Hunt
Twilio
Sqreen (now Datadog AAP)

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Neil Matatall: Neil Matatall — Content Security Policy
01:56 So, you know, probably like me, enough to be dangerous, which
05:19 Yeah, that's very cool to hear that you, you know, were
09:50 So just to kind of summarize a little bit, when we're
11:58 So like, do you remember, it was about maybe a year
14:36 So I interrupted when we were in the middle of talking
20:25 Kind of going back to, you talked about the unsafe inline
22:18 Neil, when you're building a policy then, is that the steps
28:46 It just, this is not very easy to do
30:14 In the example you had where you're adding a button and
32:39 Yeah. Now, we talked about SRI earlier. One of the challenges
34:44 We mentioned secure headers as one potential resource. Are there any
36:07 Scott Helm had a, I think it's still out there, secureheaders.io
40:02 Great, thanks for sharing that with us and for sharing it

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.