Jonathan Kingston 3/2/2015

Client side armour

Read Original

This technical article discusses client-side security standards and the W3C's efforts to combat common web attacks. It explains the concept of 'defence in depth' and technologies like HTTP Public Key Pinning (HPKP), CSP pinning (a new W3C draft), and HTTP Strict Transport Security (HSTS). These mechanisms use a 'Trust On First Use' (TOFU) approach to pin a site's security properties to the browser, helping to prevent attacks like DNS poisoning, hijacking, and man-in-the-middle attacks.

Client side armour

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week