Advertisement ยท 728 ร— 90

Posts by Mike West

Preview
GitHub - WICG/connection-allowlists Contribute to WICG/connection-allowlists development by creating an account on GitHub.

FWIW, CSP is the best thing you can use today, but it's not really built for exfiltration mitigation. We're working on github.com/wicg/connect... with that specific threat model in mind.

2 months ago 5 2 1 0

No spoilers!

4 months ago 2 0 1 0

I think @arw.me has an electric coffee mug (Ember?) keeping his beverage at a reasonable temperature for some extended period. Perhaps he could pass on a recommendation?

8 months ago 0 0 1 0

Have you considered writing more about potatoes?

1 year ago 2 0 0 0

On the other hand, knocking down fences is fun, while understanding why fences are there is usually not fun. :(

1 year ago 3 0 1 0
Modern solutions against cross-site attacks Modern solutions against cross-site attacks

Modern solutions against cross-site attacks (frederikbraun.de/modern-solut...): An article about cross-site leak attacks and browser-based defenses. You will also learn why web security best practices is always opt-in and finally how YOU can get increased security controls.

1 year ago 34 19 0 1
April King โ€” Handling Cookies is a Minefield Discrepancies in how browsers and libraries handle HTTP cookies, and the problems caused by such things.

There's a good blog post from @april.social about cookie parsing: grayduck.mn/2024/11/21/h...

And I guess it's time to dust off my broader, 2010 rant about the same:
lcamtuf.blogspot.com/2010/10/http...

Some things have improved, but cookies are still a bit of a design fail.

1 year ago 17 7 1 0
SHA2 digest generator

Do you, like me, periodically need to produce a base64-encoded SHA-2 hash of some text? Have you found existing online generator tools to be slightly annoying in some minor way that doesn't precisely fit your workflow? Well, here's another that will annoy you in _different_ ways:

sha2.it

1 year ago 3 0 0 0
Signature-based Integrity

You're entirely right. The promises signatures can make are different in kind, but hopefully no less useful. wicg.github.io/signature-ba... and wicg.github.io/signature-ba... get at the distinctions to some extent, and I'd welcome additions to those descriptions.

1 year ago 1 0 0 0
Advertisement

It's unfortunate that this is _also_ the way to discover whether food is untasty.

1 year ago 0 0 0 0
Preview
Security Signals: Making Web Security Posture Measurable At Scale

Happy to publish the effort of my last five years: Security Signals.

research.google/pubs/securit...

1 year ago 27 7 0 1
Signature-based Integrity

wicg.github.io/signature-ba... seems likely to depend on this mechanism; it's going to be necessary to spell out unambiguous approaches to those decision points that make it clear how to generate and validate signatures in a consistent way on both the server and the client.

1 year ago 0 0 0 0
RFC 9421: HTTP Message Signatures This document describes a mechanism for creating, encoding, and verifying digital signatures or message authentication codes over components of an HTTP message. This mechanism supports use cases where...

I'm skimming RFC9421's signing and validation algorithms for reasons, and it seems like the spec provides way more room for confusion about what's being signed than I'd prefer, with guidance like "Determine an order for any signature parameters...". How? ๐Ÿคท

www.rfc-editor.org/rfc/rfc9421....

1 year ago 0 0 1 0
Preview
The 2024 HTTP Workshop Day one. For the sixth time, this informal group of HTTP implementers and related "interested parties" unite in a room over a couple of days doing a HTTP Workshop. Nine years since that first event in...

Daniel Stenberg's notes from this week's HTTP Workshop are a nice way of catching up on smart folks' thoughts about the present and future of your favorite transport protocol:

Day 1: daniel.haxx.se/blog/2024/11...

Day 2: daniel.haxx.se/blog/2024/11...

Day 3: daniel.haxx.se/blog/2024/11...

1 year ago 2 1 1 0

I set up this account, then nerdsniped myself right past the process of crafting a witty and enticing "Hello, world!" post to instead spend a few minutes trying to figure out whether Bluesky supported security keys rather than email for 2FA.

It apparently doesn't. ๐Ÿคท

1 year ago 1 0 0 0