Client side armour
Read OriginalThis technical article discusses client-side security standards and the W3C's efforts to combat common web attacks. It explains the concept of 'defence in depth' and technologies like HTTP Public Key Pinning (HPKP), CSP pinning (a new W3C draft), and HTTP Strict Transport Security (HSTS). These mechanisms use a 'Trust On First Use' (TOFU) approach to pin a site's security properties to the browser, helping to prevent attacks like DNS poisoning, hijacking, and man-in-the-middle attacks.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser