Skip to content

Archive

Cookies

13 articles
Cybersecurity 23 Sep 2026 4 min read

The __Host- Cookie Prefix Constrains Cookie Scope

The __Host- Cookie Prefix Constrains Cookie Scope Cookie security depends on more than the value stored in a cookie. Scope determines which requests can carry it and which responses can attempt to replace it. For a sensitive session cookie, a broad domain rule can give sibling hosts influence that the application did not intend. The __Host- cookie name prefix gives supporting browsers a compact set of scope requirements. A cookie whose name starts with __Host- is accepted only when it is set with Secure, has Path=/, and omits the Domain attribute. The result is a host-only cookie available across paths on that host and restricted to secure transport.

Cybersecurity 22 Sep 2026 5 min read

SameSite Cookies Restrict Cross-Site Credential Sending

SameSite Cookies Restrict Cross-Site Credential Sending Cookies are ambient credentials: once stored, a browser can attach them to matching requests without application code explicitly supplying each value. That convenience also creates a security boundary. A page on one site may cause a browser to send a request to another site, and an authentication cookie attached to that request can make it act with the user’s session. The SameSite cookie attribute narrows that behavior. It tells the browser when a cookie is eligible to accompany requests whose site context differs from the site that set the cookie. The attribute is useful against classes of cross-site request forgery, but it is not a complete authorization mechanism and does not replace CSRF tokens or server-side request checks where those controls are required.

Cybersecurity 22 Sep 2026 5 min read

SameSite Cookies Constrain Cross-Site Credential Sending

SameSite Cookies Constrain Cross-Site Credential Sending Cookies are ambient credentials: once a browser stores a cookie that matches a request’s domain, path, security, and expiry rules, application code does not have to add that cookie explicitly to every request. That convenience also creates a security boundary. A page on one site can cause a browser to send requests to another site, and some of those requests may carry cookies. The SameSite attribute gives the browser another condition to evaluate before attaching a cookie. It does not change the cookie’s value or authenticate the request by itself. It controls cookie inclusion according to the relationship between the request context and the cookie’s site.

Cybersecurity 21 Sep 2026 5 min read

The __Host- Cookie Prefix Narrows Session Cookie Scope

The __Host- Cookie Prefix Narrows Session Cookie Scope A session cookie can carry a strong random identifier and still have an unnecessarily broad scope. The Domain attribute can make a cookie available across subdomains, while a path-specific cookie can coexist with another cookie of the same name. Those details matter when several applications share a registrable domain but do not share the same security boundary. The __Host- cookie-name prefix gives supporting user agents a compact rule set for a stricter cookie. A cookie whose name begins with __Host- must be set from a secure origin with Secure, must use Path=/, and must omit Domain. A user agent that implements the prefix rejects a prefixed cookie that violates those constraints.

Cybersecurity 21 Sep 2026 5 min read

SameSite Cookies Constrain Cross-Site Session Sending

SameSite Cookies Constrain Cross-Site Session Sending A session cookie is an ambient credential: once stored, the browser can attach it to matching HTTP requests without application code copying the value into each request. That convenience also creates a security boundary. A request initiated from another site can reach an application while carrying the user’s authenticated session unless cookie policy prevents it. The SameSite attribute gives the browser a rule for deciding whether a cookie may accompany a request in a cross-site context. It does not change the cookie value or authenticate the request by itself. It changes when the browser includes that cookie.

Cybersecurity 20 Sep 2026 6 min read

SameSite Cookies Reduce Cross-Site Request Attachment

SameSite Cookies Reduce Cross-Site Request Attachment Cookie-based sessions rely on browser behavior that is both useful and security-sensitive: once a cookie matches a request’s domain, path, security, and other applicable rules, the browser can attach it without application code explicitly supplying the credential. That ambient behavior makes sessions convenient, but it also creates a channel through which a request initiated from another site can arrive with authentication state. The SameSite cookie attribute narrows that channel. It tells the browser whether a cookie may accompany requests whose site context differs from the cookie’s site. The control changes credential attachment at the browser boundary; it does not turn a state-changing endpoint into an authorized operation by itself.

Cybersecurity 20 Sep 2026 5 min read

SameSite Cookies Make Site Context Part of Session Delivery

SameSite Cookies Make Site Context Part of Session Delivery HTTP cookies are ambient credentials in many web applications. Once a browser stores a session cookie, matching requests can carry it automatically; application code does not have to attach the credential to every request. That convenience also creates a security problem: a page on another site may cause the browser to issue a request to the authenticated application. The SameSite cookie attribute adds request context to the browser’s delivery decision. A cookie can still match its domain, path, expiry, and transport requirements, yet be withheld because the request is cross-site. The control therefore changes where part of the session boundary is enforced: before the credential reaches the server.

Cybersecurity 17 Sep 2026 6 min read

SameSite Cookies Enforce a Site Boundary, Not an Origin Boundary

SameSite Cookies Enforce a Site Boundary, Not an Origin Boundary An application at https://accounts.example.com uses a session cookie marked SameSite=Strict. A separate service at https://reports.example.com is operated by another team and has a distinct origin. The two hosts are isolated by the browser’s origin model for many web capabilities, yet a request from one can still be classified as same-site with the other. The cookie attribute is enforcing a site boundary, not duplicating the same-origin policy.

Cybersecurity 16 Sep 2026 7 min read

SameSite Cookies Draw a Site Boundary That Is Broader Than Origin

SameSite Cookies Draw a Site Boundary That Is Broader Than Origin Two HTTPS applications can be isolated by the browser’s same-origin policy yet still occupy the same cookie site. A service at accounts.example.com and another at shop.example.com have different origins because their hosts differ, but cookie policy can classify their request context at a broader site boundary. That gap matters when SameSite is treated as if it were equivalent to origin isolation.

Cybersecurity 15 Sep 2026 5 min read

SameSite Cookies Move CSRF Control Into Request Context

A browser can send an authenticated request that the account holder never intended to initiate. The target site may receive a valid session cookie, see a legitimate account, and process a state change even though the request originated from another site. The credential is ambient: browser attachment, not explicit application code, supplies it. The SameSite cookie attribute changes that attachment decision. Rather than asking the server to distinguish hostile requests after every cookie arrives, it gives the user agent policy for deciding whether a cookie accompanies requests in cross-site contexts. That moves part of the CSRF boundary into browser request processing, but only for cookies covered by the attribute and only according to the site’s relationship and request context defined by browser policy.

Cybersecurity 14 Sep 2026 6 min read

SameSite Cookies Bound Cross-Site Credential Sending

SameSite Cookies Bound Cross-Site Credential Sending A browser can send an authenticated request that the account holder never intended to make. The application may see a valid session cookie, a normal HTTP method, and a request arriving over TLS. None of those facts proves that the request originated from a page the application trusts. That gap is central to cross-site request forgery. Cookie-based sessions are ambient credentials: once stored, they can be attached by the browser according to cookie rules rather than by deliberate application code at each request. The SameSite attribute changes those rules by restricting cookie attachment in cross-site contexts.

Tech 13 Sep 2026 6 min read

Browser Cookies and Cached Files Serve Different Jobs

A browser can remove cached images and scripts without signing you out of a website, yet clearing site cookies can end a signed-in session even when the page files remain stored locally. Both actions are often grouped under “clear browsing data,” but they affect different parts of browser state. Cookies and the HTTP cache solve separate problems. Cookies let a site associate small pieces of state with later requests. The cache lets a browser reuse eligible responses instead of transferring the same representation again whenever a page needs it.

Cybersecurity 02 Sep 2026 5 min read

Practical CSRF Defense with SameSite Cookies and Tokens

Cross-site request forgery (CSRF) abuses the fact that browsers can automatically attach a user’s cookies to requests. If a state-changing endpoint trusts only the presence of an authenticated cookie, another site may be able to trigger that endpoint from the user’s browser. Modern cookie controls reduce the attack surface, but robust applications still need to reason about request semantics and trust boundaries. Understand the condition that makes CSRF possible A typical CSRF attack needs three ingredients: