BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Past the Bouncer: The Limits of CSP\, Eleven Years I
 n\n   Tags: Intermediate | AppSec Village | Creator Talk/Panel\n   When: S
 aturday\, Aug 8\, 13:30 - 13:59 PDT\n   Where: LVCCW Level 1 Hall 2 604 (A
 ppsec Village) Main Stage - [1]Map\n\n   Description:\n\n   CSP turned ele
 ven this year. It is the standard the web ultimately\n   adopted to decide
  which scripts a page is allowed to load and execute\,\n   and it now sits
  at the center of how we think about XSS mitigation\,\n   third-party scri
 pt risk\, and client-side supply-chain compromise.\n\n   The problem is th
 at CSP was designed as a fetch-time control. It\n   evaluates origins\, no
 nces\, hashes\, and directives when resources are\n   requested\, yet it i
 s often expected to provide guarantees about what\n   trusted code does af
 ter execution begins. The bypass literature tells\n   a different story.\n
 \n   This talk examines five representative CSP bypass classes\, and uses\
 n   them to expose the gap between controlling what may be loaded and\n   
 governing behaviour at runtime. It also raises broader questions of\n   sc
 ript governance\, supply-chain security\, and the distinction between\n   
 fetch-time and runtime security controls.\n\n   I conclude by introducing 
 an open learning platform that contains a\n   comprehensive catalogue of C
 SP bypass techniques.\n\n   SpeakerBio:  Pedro Fortuna\n\n   Pedro Fortuna
  is a security researcher\, entrepreneur\, and CTO of\n   Jscrambler. For 
 more than 15 years\, his work has focused on web\n   security\, client-sid
 e security\, reverse engineering\, malware analysis\,\n   and software sup
 ply chain threats. He is the author of multiple\n   security patents\, a c
 ontributor to OWASP\, and a member of the PCI\n   Security Standards Counc
 il Board of Advisors.\n\n   Pedro regularly presents security research at 
 international\n   conferences and spends much of his time investigating ho
 w modern web\n   applications fail in practice\, from browser-side attacks
  and web\n   skimming campaigns to the security implications of emerging\n
    technologies.\n\n   '\n\n   1. #LVCCW_Level1_Hall2\n\n\n
DTEND:20260808T205900Z
DTSTART:20260808T203000Z
LOCATION:AppSec Village - LVCCW Level 1 Hall 2 604 (Appsec Village) Main St
 age
SUMMARY:Past the Bouncer: The Limits of CSP\, Eleven Years In
END:VEVENT
END:VCALENDAR
