But CSP is off to a slow start and is not implemented on the vast majority of web sites. Perhaps the difficulty implementing CSP is to blame?
This post examines a case study deploying CSP and has some recommendations for the social media companies to make it easier to implement CSP.
The Content Security Policy (CSP) is a powerful mechanism to prevent Cross Site Scripting (XSS) attacks which accounts for 84% of all security vulnerabilities in web sites. So you would think that such a magic bullet would be widely deployed and promoted.
Think again: CSP is implemented on less than 0.5% of web sites. Further, of those implementing sites, less than 3% are using CSP in the recommended manner that effectively mitigates Cross Site Scripting attacks. In fact, out of 21,823 sites surveyed, less than 0.02% of sites are effectively using CSP.
These are the results of a CSP survey to determine the level of CSP adoption in public web sites.
Embedthis products including the Appweb and GoAhead web servers have supported a variety of SSL stacks for secure connectivity including: OpenSSL, mbed TLS, MatrixSSL and NanoSSL. However, this has often required separately downloading and building the SSL software. For some SSL stacks, this can be a long and non-trivial exercise to build the SSL stack for your selected operating system.
SSL is increasingly becoming mandatory and not just an option. Securely authenticating users and controlling access to a management interface requires SSL. Further, the emerging HTTP/2 protocol will use SSL by default. Consequently, we have been searching for a simpler way to offer secure SSL connectivity out-of-the-box.
CGI for web applications may appear simple and easy, but it is slow, clumsy, insecure and ancient.
Stop using it!
There are much better alternatives for nearly every use case.
It has been a hectic few months with plenty of releases and new initiatives. GoAhead and Appweb 5 have been updated and Appweb 6 has been released. Both products have started to make extensive use of the Pak package manager and we have a growing set of components available on the Pak Catalog.
But what does the future hold?