Of course CSP does not allow a way to say -> browser controls are okay. Hence, a debate is quite welcome on whether such a specification is needed.
57 karma · joined April 1, 2014
http://lnkd.in/dE9mzyw
Of course CSP does not allow a way to say -> browser controls are okay. Hence, a debate is quite welcome on whether such a specification is needed.
And one of the most common attacks aka. malicious firmware is prevented by using secure boot.
Many other classes of attacks like forcing the microcontroller to delete all its data, opening up the debug JTAG port of the microcontroller, preventing the log of certain security events etc. can be achieved with the right settings.
Though these are just remote possibilities with high levels of complexity, so is changing a production design of a board.
The same applies to my wall-clock (which uses a single battery)
> For disposable addresses you have mailinator.com
> For normal ids, there are quite a lot from mail.com .. or you could go to yahoo or outlook ...
> Your ISP must have provided you an id to you too.
All of them work.
But yet it is brilliant !
For example: WhiteHat Aviator.
If you are comfortable changing settings of the browser, you could disable most of the google connections from the browser. [The first things I recommend changing is the search URL, disable auto-completion, bad site checking etc.] Then you have the do not track header ..
Of course, if browsing privacy is your biggest concern, the safest browser is Lynx ;) [Though not truly practical for most cases]
I personally find aviator to be more trustworthy at this point though.
Lorem ipsum :)
However, the lack of the same-origin policy in WebSockets makes the presence of the same-origin policy in XMLHttpRequests questionable. I am just talking about this part where the browser does not have to restrict a connection to any origin from a given website without even a need for a CORS like whitelist.