
Behind the Firewall ft. Trevor Murphy
Security headers are supposed to make things simpler, but what happens when they're misunderstood? Pentester, Trevor Murphy has spent the last five years focused on client-side security, and he’s seen the landscape shift dramatically. “When I first started in pen testing, web app security was a lot more fragmented. You had a separate header for each directive, one rule per line. Now, with Content Security Policies (CSPs), it’s all condensed into…




