I blogged about Content Security Policy about 2 year ago when it was still called 'Site Security Policy'.
It started as a specification and an add-on, and turned into a patch a bit later. Finally it made it into Firefox 4 beta 1.
I think CSP is the next web security revolution, so make yourself aware of how it works and the implications.