Reply to post: What's the point of CSP anyway?

uBlock Origin ad-blocker knocked for blocking hack attack squawking

ThatOne Silver badge
Paris Hilton

What's the point of CSP anyway?

Somebody please help me understand:

CSP reports tell the website owner if malicious scripts have been injected. They don't alert the user, they only alert the website owner (for instance Equifax). Isn't it?

If that's true, what's the point of those reports? 99% of big websites won't care (if only because CSP messes with ad delivery I guess). Those who might care (the potential victims) don't get to see those violation reports anyway if I got it right (at least not before it's too late anyway). So, what's the point in CSP?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon