DrupalCon Vienna 2017: Using your headers for better security
About this talk
This talk explores common web security vulnerabilities and the new HTTP headers standardized for modern browsers to enhance website security and privacy. The speaker discusses the impact of these vulnerabilities and demonstrates how new headers and browser features can be implemented within Drupal 8. Additionally, the session includes a strategy for segmenting site responsibilities across subdomains and shares insights on the development of a module that automatically applies Content Security Policy using Drupal 8's libraries API.