just sent 4 security / vulnerability reports about csp bypasses
-
-
Bypassing CSP makes XSS / code exec even worse as it allows making network requests (sending data, script src) which should be blocked by CSP. Some are generic / common (work in a load of sites due to oversights) and some are site-specific (like forgetting to add it to one page).
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.