731: Client side security, XSS attacks & CSP with Stripe’s Alex Sexton

731: Client side security, XSS attacks & CSP with Stripe’s Alex Sexton

Scott and Wes are joined by security expert, Alex Sexton of Stripe to cover all things: client security, XSS, attack vectors, and CSP (content security policy). Show Notes 00:00 Welcome to Syntax! 00:31 Brought to you by Sentry.io. 00:57 Who is Alex Sexton? 04:44 Stripe dashboard is a work of art. 05:08 Tell us about the design system. React Aria 08:59 Who develops the iOS app? 09:50 Stripe’s CSP (content security policy). 12:50 What even is a content security policy? Content Security Policy explanation 13:57 Douglas Crockford of Yahoo on security. Douglas on GitHub 15:13 Security philosophy. 16:59 What about inline styles and inline JavaScript? 19:41 How do we safely set inline styles from JS? 20:20 Setting up with meta tags. 22:52 What are common situations that require security exceptions? 26:24 Potential damage with inline style tags. 32:45 Looping vulnerabilities. 36:32 What about JavaScript injection? 37:09 Myspace Samy Worm. Myspace Samy Worm Wiki Sentry.io Security Policy Reporting 42:02 Does a CSP stop code from running in the console? 43:28 What are some general security best practices? 46:35 Strategies for rolling out a CSP. 51:49 Final tip, Strict Dynamic. Strict Dynamic 56:36 Where does the CSP live within Stripe? Original Black Friday story 59:35 One last story. 01:01:20 Sick Picks + Shameless Plugs Sick Picks + Shameless Plugs Alex: Wes Bos’ Instagram Hit us up on Socials! Syntax: X Instagram Tiktok LinkedIn Threads Wes: X Instagram Tiktok LinkedIn Threads Scott:X Instagram Tiktok LinkedIn Threads Randy: X Instagram YouTube Threads

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(1035)

1035: Why everyone is moving to Stylex?

1035: Why everyone is moving to Stylex?

Meta’s StyleX compiles thousands of styles into a few reusable class names at build time—zero runtime, fully type-safe. Scott and Wes break down why it’s suddenly everywhere, and why it might be the b...

2 Sep 26min

1034: Omarchy Quattro Release

1034: Omarchy Quattro Release

Grokbot actually earns its keep, Cursor takes a swing at GitHub with Origin, and Omarchy Quattro ships pre-wired for nine coding agents. Plus: the GitHub outage post-mortem, a compromised Rust crate, ...

31 Aug 1h 15min

1033: 8 New CSS, JS and HTML Features You Should Know

1033: 8 New CSS, JS and HTML Features You Should Know

Scott and Wes run through eight new CSS, JS, and HTML features landing in browsers; including the relative alpha() color function, the progress() function for calculating values between units, Promise...

26 Aug 18min

1032: Stripe Buys OpenRouter for $7B

1032: Stripe Buys OpenRouter for $7B

Scott and CJ break down Stripe's $7B acquisition of OpenRouter, the SvelteKit 3 release candidate, and their first look at TanStack Charts. Plus Zed's new Delta editor, stealing reasoning traces from ...

24 Aug 1h 7min

1031: My Coding Skills Are Atrophying

1031: My Coding Skills Are Atrophying

Scott and Wes answer your questions about coding in the AI era, atrophying skills from too much autocomplete, whether it’s finally time to leave VS Code, chasing flow state with agents, and which sing...

19 Aug 57min

1030: AI Assistant Hacks Gym

1030: AI Assistant Hacks Gym

An AI assistant goes rogue and hacks a gym website, a $9k surprise Cloudflare bill lands in someone’s inbox, and AI subscriptions start promising unlimited usage. Plus Meta’s Muse Glimmer, Agent Plugi...

17 Aug 1h 24min

1029: The Workflow of the Future With Zed

1029: The Workflow of the Future With Zed

Nathan Sobo joins Scott and Wes to explain why Zed was built in Rust, how GPUI works, and what happens to editors once agents write most of the code. They also talk about DeltaDB, Zed’s new Git-compat...

12 Aug 59min

1028: Cloudflare Wallets

1028: Cloudflare Wallets

Cloudflare is rolling out crypto wallets with claimable handles as identity, and a real React compiler finally landed for regular hooks-based code. Plus: OpenAI's pricing war, Vue Vapor benchmarks, Gi...

10 Aug 1h 18min

Populärt inom Politik & nyheter

aftonbladet-krim
svenska-fall
fordomspodden
p3-krim
rss-krimstad
en-runda-till
flashback-forever
aftonbladet-daily
politiken
rss-vad-fan-hande
rss-expressen-dok
rss-sanning-konsekvens
svd-ledarredaktionen
motiv
omni-podd
kungligt
spar
grans
rss-krimreportrarna
rss-frandfors-horna