Fifteen Years is a Solid Run

After fifteen years of being on, I've decided that it was time to move to a new domain.

$ whois
Domain     : TWOEVILS.ORG
Domain ID  : D80038331-LROR
Status     : Live
Registered : 2001-11-20
Expiry     : 2017-11-20

When I first registered the domain, I used exclusively, but nobody ever got the joke. “Who's lesser?” I eventually switched to using which made even less sense and still garnered weird looks.

$ whois
Domain     :
Domain ID  : DOM-388773
Status     : Live
Registered : 2016-03-27
Expiry     : 2017-03-27

Hopefully I (and everybody else) will still find just as amusing in 2032.

[Category: Personal] [Permalink]

CSP on (AMO)

Content Security Policy (CSP) is one of the most important steps a website can take to reduce its vulnerability profile. Implemented properly, it can reduce the risk of cross-site scripting (XSS) attacks to near zero.

AMO is one of the highest profile sites both at Mozilla and on the internet at large. An XSS attack against it could lead millions of Firefox users to unwittingly install addon exploits. After six years of hard work, the Mozilla Infosec team and the AMO team successfully implemented CSP.

You can read my write-up of our experiences on the Mozilla Hacks blog.

[Category: Security] [Permalink]