Thoughts on CSP

The challenge CSP faces in mitigating XSS vulnerabilities can be (over)simplified as follows: How on earth can we tell the difference betw »