I wrote a little while back about the AppSec Serenity Prayer and talked about things you can and can’t control in terms of your application security. The recent BrowseAloud incident is a perfect reason to talk about this again and provide some real-world examples of how CSP and SRI could have prevented/mitigated this attack.