The Future of Cookies - Anders Abel - NDC Security 2024

แชร์
ฝัง
  • เผยแพร่เมื่อ 20 ส.ค. 2024
  • This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity #ndcconferences #security #developer #softwaredeveloper
    Attend the next NDC conference near you:
    ndcconferences...
    ndc-security.com/
    Subscribe to our TH-cam channel and learn every day:
    /‪@NDC‬
    Follow our Social Media!
    / ndcconferences
    / ndc_conferences
    / ndc_conferences
    Cookies has been a basic foundation for web development for decades. It is used widely by applications and security solutions, but unfortunately also by trackers threatening our privacy.
    In 2020 Google changed the default SameSite behaviour for cookies to Lax and Safari enabled full 3rd party cookie blocking. These changes required updates to a vast range of sites. In 2022 Firefox introduced a unique concept of cookie buckets to improve privacy, while still trying to not break single sign on and other valid solutions.
    Using cookies and making sure they work across different browsers is harder than ever. And there is more to come...

ความคิดเห็น • 7

  • @capability-snob
    @capability-snob 4 หลายเดือนก่อน +4

    There's an even easier way to ensure your website was never vulnerable to CSRF or clickjacking: these are both instances of the Confused Deputy Problem. It turns out that when Norm Hardy first wrote about this problem in 1988, he also described the solution for it. If you've been building systems the way he described, you've looked on in bewilderment at the rest of the world as it grapples to plug holes in a legacy security model.

  • @deefdragon
    @deefdragon 4 หลายเดือนก่อน +2

    The alarm triggering at the 20 minutes was very ammusing

  • @Ostap1974
    @Ostap1974 4 หลายเดือนก่อน +1

    I thunk the cookie jar approach with http header that would whitelist origins where from the cookies are accepted, would be very robust and reliable solution.

  •  4 หลายเดือนก่อน

    Very nice talk.

  • @Soliber
    @Soliber 4 หลายเดือนก่อน +3

    So everyone wants to fix it so ads can still track us, but screw security 😅

  • @abylay9288
    @abylay9288 4 หลายเดือนก่อน +3

    *biscuits