Conversation

I'm not sure who needs to hear this but... X-XSS-Protection security header is dead. It's only for backwards compatibility, but recently (2019) vulnerabilities have been discovered and it's been used successfully to attack apps. Use Content Security Policy (CSP) instead. 🌞
16
377
It may still make sense to set these for IE11 but I don't think anyone should be *recommending* setting it as if it's a best practice. Also, as you explain here, the main thing that actually needs to be done for legacy browsers is *disabling* the unsafe filtering.
1
1