Remove tag risk-based-approach
article thumbnail

Locking Down Your Website Scripts with CSP, Hashes, Nonces and Report URI

Troy Hunt

I run a workshop titled Hack Yourself First in which people usually responsible for building web apps get to try their hand at breaking them. That's pretty much XSS 101 - just get an alert box to fire - and reflecting a script tag is one of the most fundamental techniques attackers use to run their script on your website. Using Nonces.

article thumbnail

The Hacker Mind Podcast: Surviving Stalkerware

ForAllSecure

Cherne: The name of this talk at Black Hat this year is a “Survivor-centric, Trauma-informed Approach to Stalkerware.” Black Mirror brainstorms, a workshop in which you create Black Mirror episodes. ” Vamosi: And on that first day of Black Hat, not everybody was impressed. That would be something to consider.