Hacker News new | past | comments | ask | show | jobs | submit login

How?



CSP reporting is an unprotected form, in itself a vulnerability.

The author of the article is biased as he made a SaaS product for CSP reporting.

CSP reporting should be for local debugging only.


I'm sorry, I'm still not following. How can CSP reporting be used by marketers? It requires a header sent from the server, so it's not like a tracking pixel that can be added by a third party. And I'm not sure about local debugging only, locally it offers no benefits over just viewing the devtools console, whereas it offers a lot of benefits when enabled on users of your sites.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: