Not sure what Content-Security-Policy and Strict-Transport-Security are about? Your web apps are at risk! Security is crucial but can be hard to get right. Luckily for web developers, the HTTP protocol comes with well-thought-out security specifications. Modern browsers implementing those security features are capable of doing much of the heavy lifting for us. It is our responsibility to put the browsers on guard. This talk explores which security headers are especially useful along with when and how to use them.
Wei is a full-time open source software developer, passionate about beautiful code and cryptocurrencies. She’s currently leading the development effort of Hive web wallet - an elegant cryptocurrency wallet. She’s also a core maintainer of bitcoinjs-lib and co-organizes SingaporeJS meetups and local NodeSchool workshops.
JSConf.Asia is the JavaScript, web and mobile developer conference for Asia. Amara Sanctuary, Singapore - 20 + 21 November 2014.
Source:
License: For reuse of this video under a more permissive license please get in touch with us. The speakers retain the copyright for their performances.
Watch video Wei Lu: HTTP Headers - The Simplest Security - JSConf.Asia 2014 online without registration, duration 25 minute 52 second in high hd quality. This video was added by user JSConf 13 January 2015, don't forget to share it with your friends and acquaintances, it has been viewed on our site 7 thousand once and liked it 98 people.