Re: Enhancing product security with CSP for internal pages

2014-04-15 Thread Frederik Braun
On 15.04.2014 22:45, Neil wrote: > Frederik Braun wrote: > >> On 15.04.2014 00:43, Neil wrote: >> >> >>> Frederik Braun wrote: >>> A few months ago I had the idea to add a Content Security Policy (CSP) to our internal pages, like about:newtab for example. >>> So this just applies

Re: Enhancing product security with CSP for internal pages

2014-04-15 Thread Neil
Frederik Braun wrote: On 15.04.2014 00:43, Neil wrote: Frederik Braun wrote: A few months ago I had the idea to add a Content Security Policy (CSP) to our internal pages, like about:newtab for example. So this just applies to about: pages? Primarily yes. I think some people are alread

Re: Enhancing product security with CSP for internal pages

2014-04-15 Thread Frederik Braun
On 15.04.2014 00:43, Neil wrote: > Frederik Braun wrote: > >> A few months ago I had the idea to add a Content Security Policy (CSP) >> to our internal pages, like about:newtab for example. >> > So this just applies to about: pages? > Primarily yes. I think some people are already working on oth

Re: Enhancing product security with CSP for internal pages

2014-04-14 Thread Neil
Frederik Braun wrote: A few months ago I had the idea to add a Content Security Policy (CSP) to our internal pages, like about:newtab for example. So this just applies to about: pages? -- Warning: May contain traces of nuts. ___ dev-platform mailin

Enhancing product security with CSP for internal pages

2014-04-14 Thread Frederik Braun
Hi folks, For those who don't know me, I'm a Security Engineer working on Firefox OS (mostly Gaia and Gecko things). I have been pursuing a security goal for quite some time now but haven't yet announced this to throughout the project. A few months ago I had the idea to add a Content Security Pol