The Future of Cookies - Anders Abel - NDC Security 2024

  Рет қаралды 5,828

NDC Conferences

NDC Conferences

4 ай бұрын

This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity #ndcconferences #security #developer #softwaredeveloper
Attend the next NDC conference near you:
ndcconferences.com
ndc-security.com/
Subscribe to our KZfaq channel and learn every day:
/‪@NDC‬
Follow our Social Media!
/ ndcconferences
/ ndc_conferences
/ ndc_conferences
Cookies has been a basic foundation for web development for decades. It is used widely by applications and security solutions, but unfortunately also by trackers threatening our privacy.
In 2020 Google changed the default SameSite behaviour for cookies to Lax and Safari enabled full 3rd party cookie blocking. These changes required updates to a vast range of sites. In 2022 Firefox introduced a unique concept of cookie buckets to improve privacy, while still trying to not break single sign on and other valid solutions.
Using cookies and making sure they work across different browsers is harder than ever. And there is more to come...

Пікірлер: 7
@capability-snob
@capability-snob 4 ай бұрын
There's an even easier way to ensure your website was never vulnerable to CSRF or clickjacking: these are both instances of the Confused Deputy Problem. It turns out that when Norm Hardy first wrote about this problem in 1988, he also described the solution for it. If you've been building systems the way he described, you've looked on in bewilderment at the rest of the world as it grapples to plug holes in a legacy security model.
@deefdragon
@deefdragon 4 ай бұрын
The alarm triggering at the 20 minutes was very ammusing
@Ostap1974
@Ostap1974 3 ай бұрын
I thunk the cookie jar approach with http header that would whitelist origins where from the cookies are accepted, would be very robust and reliable solution.
@Soliber
@Soliber 4 ай бұрын
So everyone wants to fix it so ads can still track us, but screw security 😅
3 ай бұрын
Very nice talk.
@abylay9288
@abylay9288 4 ай бұрын
*biscuits
How I Met Your Data - Troy Hunt - NDC Sydney 2024
59:43
NDC Conferences
Рет қаралды 1,9 М.
How Many Balloons Does It Take To Fly?
00:18
MrBeast
Рет қаралды 193 МЛН
39kgのガリガリが踊る絵文字ダンス/39kg boney emoji dance#dance #ダンス #にんげんっていいな
00:16
💀Skeleton Ninja🥷【にんげんっていいなチャンネル】
Рет қаралды 8 МЛН
Clown takes blame for missing candy 🍬🤣 #shorts
00:49
Yoeslan
Рет қаралды 43 МЛН
ASP.NET Core Meets Owasp Top 10 - Anders Abel - NDC Security 2022
54:25
NDC Conferences
Рет қаралды 3,5 М.
Jeevan Singh -- The Future of Application Security Engineers
46:59
The Application Security Podcast
Рет қаралды 2,3 М.
An Introduction to Residuality Theory - Barry O'Reilly - NDC London 2024
54:15
Getting API security right - Philippe De Ryck - NDC London 2023
51:49
NDC Conferences
Рет қаралды 26 М.
So You Think You Know Git - FOSDEM 2024
47:00
GitButler
Рет қаралды 1 МЛН
When Cybercriminals with Good OpSec Attack
49:01
RSA Conference
Рет қаралды 180 М.
Continuous Delivery for Legacy Code - Richard Groß - NDC London 2024
48:37
Что делать если в телефон попала вода?
0:17
Лена Тропоцел
Рет қаралды 3 МЛН
Как распознать поддельный iPhone
0:44
PEREKUPILO
Рет қаралды 2,3 МЛН