Understanding The Web Security Model, Part III: Basic Principles and the Origin Concept
Note: This is one of those posts that is going to be best read on the Web, especially if you read your email using Gmail or the like, as it will tend to mangle some of the HTML features. This is Part III of my series on the Web security model (see parts I and II for background on how the Web works). In this part, I cover the primary unit of Web security, the origin and some of its implications. Unlike applications or e-books, the experience of using the Web is not confined to content provided by one vendor. Instead, even if you start on one site, many of your activities on that site will take you to other sites. Consider, for instance, the experience of searching for something using Google. Once you execute the search, Google then gives you a set of links, many of which take you to another site. Google's relationship to those sites is arms-length at best: it doesn't control them and doesn't bear any responsibility for their content beyond some vague assertion that this might be somethi
Understanding The Web Security Model, Part III: Basic Principles and the Origin Concept Posted by ekr on 21 Mar 2022 Note: This is one of those posts that is going to be best read on the Web, especially if you read your email using Gmail or the like, as it will tend to mangle some of the HTML features. This is Part III of my series on the Web security model (see parts I and II for background on how the Web works). In this part, I cover the primary unit of Web security, the origin and some of its implications. The Web Security Guarantee # Unlike applications or e-books, the experience of using
Explore this link on the map →saved by
related reading
- Understanding The Web Security Model, Part IV: Cross-Origin Resource Sharing (CORS)educatedguesswork.org
- Cross-Site Scripting (XSS) | Computer Securitytextbook.cs161.org
- Cross-Site Request Forgery (CSRF) | Computer Securitytextbook.cs161.org
- All learning materials - detailed | Web Security Academyportswigger.net
- Introduction to CORS for Go programmers - Eli Bendersky's websiteeli.thegreenplace.net
- Rediscovering the Small Web - Neustadt.frneustadt.fr
- What is CORS? Complete Tutorial on Cross-Origin Resource Sharingauth0.com
- Against an Increasingly User-Hostile Web - Neustadt.frneustadt.fr
- passwords - Demystifying Web Authentication (Stateless Session Cookies) - Information Security Stack Exchangesecurity.stackexchange.com
- Part 2: Complete User Authentication: Sessions vs JWT | by Nick Jagodzinski | Mediummedium.com
- Using HTTP cookies - HTTP | MDNdeveloper.mozilla.org
- The Agentic Web and Original Sin – Stratechery by Ben Thompsonstratechery.com