GitHub's Content Security Policy journey
githubengineering.com
githubengineering.com
One issue I have with CloudFront is that they don't support setting/configuration of any of the content security headers. Configuring HTTPS with CloudFront is a breeze nowadays, but if you want to take advantage of header-based features, you're out of luck. I imagine a number of other hosting solutions have this problem, too.
CSP can be set via a meta tag:
<meta http-equiv="X-Content-Security-Policy" content="..." />
But I'm not sure how widely that is supported or what the caveats are.This is a pretty great tool to build / analyze your CSP records.
If the context is not "computer science" but instead "web technologies" or "computer security," then CSP most certainly stands for "Content Security Policy." It's perfectly possible to know one meaning but not the other; as someone with a CS degree working in internet security, I'd heard of communicating sequential processes once or twice before, but they were at the back of my mind in comparison to content security policies.
But of course, since not everyone on HN works in security or on web technologies, it would've been more "widely understood by others" if the title expanded to say "Content Security Policy" instead.