Daily Shaarli

All links of one day in a single page.

April 12, 2016

GitHub’s CSP journey - GitHub Engineering

We shipped subresource integrity a few months back to reduce the risk of a compromised CDN serving malicious JavaScript. That is a big win, but does not address related content injection issues that may exist on GitHub.com itself. We have been tackling this side of the problem over the past few years and thought it would be fun, and hopefully useful, to share what we have been up to.

Being tired isn’t a badge of honor — Signal v. Noise

Whenever I speak at a conference, I try to catch a few of the other presentations.