731: Client side security, XSS attacks & CSP with Stripe’s Alex Sexton

731: Client side security, XSS attacks & CSP with Stripe’s Alex Sexton

Scott and Wes are joined by security expert, Alex Sexton of Stripe to cover all things: client security, XSS, attack vectors, and CSP (content security policy). Show Notes 00:00 Welcome to Syntax! 00:31 Brought to you by Sentry.io. 00:57 Who is Alex Sexton? 04:44 Stripe dashboard is a work of art. 05:08 Tell us about the design system. React Aria 08:59 Who develops the iOS app? 09:50 Stripe’s CSP (content security policy). 12:50 What even is a content security policy? Content Security Policy explanation 13:57 Douglas Crockford of Yahoo on security. Douglas on GitHub 15:13 Security philosophy. 16:59 What about inline styles and inline JavaScript? 19:41 How do we safely set inline styles from JS? 20:20 Setting up with meta tags. 22:52 What are common situations that require security exceptions? 26:24 Potential damage with inline style tags. 32:45 Looping vulnerabilities. 36:32 What about JavaScript injection? 37:09 Myspace Samy Worm. Myspace Samy Worm Wiki Sentry.io Security Policy Reporting 42:02 Does a CSP stop code from running in the console? 43:28 What are some general security best practices? 46:35 Strategies for rolling out a CSP. 51:49 Final tip, Strict Dynamic. Strict Dynamic 56:36 Where does the CSP live within Stripe? Original Black Friday story 59:35 One last story. 01:01:20 Sick Picks + Shameless Plugs Sick Picks + Shameless Plugs Alex: Wes Bos’ Instagram Hit us up on Socials! Syntax: X Instagram Tiktok LinkedIn Threads Wes: X Instagram Tiktok LinkedIn Threads Scott:X Instagram Tiktok LinkedIn Threads Randy: X Instagram YouTube Threads

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(1044)

1044: Ruby on Rails is Dead

1044: Ruby on Rails is Dead

Scott, Wes, and CJ ask whether Ruby on Rails is really dead (and whether Rust is just Rails you don't have to read), then dig into Meta's new Muse agent, which is free, comes with its own VM, and is a...

5 Okt 1h 20min

1043: I’m Using GPUI For Everything

1043: I’m Using GPUI For Everything

Scott and Wes ditch Electron and Tauri for GPUI, the GPU accelerated Rust UI framework from the Zed team. They get into its React-like API, styling that feels a lot like Tailwind, GPUI Kit components,...

30 Sep 32min

1042: Is the Jev Hype Overblown?

1042: Is the Jev Hype Overblown?

Is Jev actually a leap forward for classification or just hype and fake demos? We dig in, plus Claude Code’s new AGENTS.md support, TinyCast (the free, open-source Raycast alternative), an iPhone Fold...

28 Sep 1h 22min

1041: What are normies using AI for?

1041: What are normies using AI for?

Scott and Wes talk about how non-developers are actually using AI today. They also cover the stuff they don’t think holds up, like AI-staged listings and automated marketing. Show Notes 00:00 Intro...

23 Sep 47min

1040: Developing for the iPhone Duo

1040: Developing for the iPhone Duo

Scott, Wes, and CJ break down developing for the iPhone Duo with the Device Posture and Viewport Segments APIs, plus the React 19.3 release and Pi’s new Radius platform. Also on deck: Tailwind joining...

21 Sep 1h 33min

1039: Should You Quit Your Job?

1039: Should You Quit Your Job?

Scott and Wes dig into a listener mailbag full of AI questions: how to bill freelance work when the tools make you faster, whether coding still matters in interviews, and if the AI bubble is about to ...

16 Sep 1h

1038: OpenAI Releases GPT 6 Astra

1038: OpenAI Releases GPT 6 Astra

Wes and CJ dig into OpenAI’s GPT‑6 Astra; the massive jump in computer use, the wild Blender MCP 3D demos, and whether all the AGI talk actually holds up. Plus Hugging Face’s robot duck, Vitest 5 and ...

14 Sep 1h 25min

1037: WebMCP is here (and you should care)

1037: WebMCP is here (and you should care)

Scott and Wes talk about WebMCP with Sarah Drasner and Dominic Farolino from the Chrome team, which is the new W3C standard that lets your site hand real tools to an agent. They cover the security mod...

9 Sep 56min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
aftenpodden-usa
forklart
popradet
fotballpodden-2
stopp-verden
det-store-bildet
dine-penger-pengeradet
rss-espen-lee-usensurert
nokon-ma-ga
rss-gukild-johaug
hanna-de-heldige
aftenbla-bla
rss-ness
frokostshowet-pa-p5
bt-dokumentar-2
e24-podden
rss-penger-polser-og-politikk
ta-dokumentar