Skip to content

Archive

Web Security

130 articles
Cybersecurity 22 Sep 2026 6 min read

Certificate Transparency Exposes Certificate Issuance to Public Audit

Certificate Transparency Exposes Certificate Issuance to Public Audit A publicly trusted TLS certificate is an assertion made by a certificate authority. Traditional PKI gives clients a way to validate that assertion against trusted roots, but successful path validation alone does not make certificate issuance publicly visible. Certificate Transparency, commonly abbreviated CT, adds an audit layer. Participating logs accept certificate entries and commit them to append-only data structures. The resulting evidence lets clients, domain operators, and monitors detect certificates that have entered the public Web PKI, including certificates an operator did not expect to exist.

Cybersecurity 21 Sep 2026 5 min read

Trusted Types Put DOM Injection Sinks Behind Policies

Trusted Types Put DOM Injection Sinks Behind Policies DOM-based cross-site scripting often appears at the last step of a data flow. A value moves through application code as an ordinary string, then reaches an API that interprets it as HTML, script, or a script URL. The dangerous boundary is not the string alone; it is the moment that string enters an injection sink. Trusted Types changes that boundary. In supporting browsers, an application can require covered sinks to receive objects such as TrustedHTML, TrustedScript, or TrustedScriptURL instead of raw strings. Those objects are created through policies defined by the application.

Cybersecurity 21 Sep 2026 5 min read

Subresource Integrity Pins External Assets to Expected Content

Subresource Integrity Pins External Assets to Expected Content A page that loads JavaScript or CSS from another host gives that host a direct path into the page’s execution or presentation context. HTTPS protects the transfer against network tampering, but it does not tell the browser whether the server returned the exact asset the application intended to use. Subresource Integrity (SRI) adds a content check. The document carries cryptographic metadata for a resource. After fetching the bytes, the browser computes the relevant digest and compares it with the metadata before accepting the resource.

Cybersecurity 21 Sep 2026 4 min read

Permissions Policy Limits Powerful Browser Features

Permissions Policy Limits Powerful Browser Features A web page can contain code from several trust domains while still sharing access to browser capabilities. First-party scripts, third-party widgets, and nested frames may all execute inside one application surface. Browser permission prompts remain important, but an application can narrow the set of documents that are eligible to request or use selected features before a prompt becomes relevant. Permissions Policy provides that boundary. A response header declares which origins may use controlled features in the document and its frame tree. The policy does not grant a user permission. It constrains feature availability within the browser.

Cybersecurity 21 Sep 2026 5 min read

HSTS Pins HTTPS Policy in the Browser

HSTS Pins HTTPS Policy in the Browser An HTTPS redirect does useful work only after an HTTP request reaches the server. That first cleartext request remains a weak point: a network attacker able to alter traffic can interfere before the browser receives the redirect. HTTP Strict Transport Security, or HSTS, moves part of that decision into the browser. After receiving a valid Strict-Transport-Security header over HTTPS, a conforming user agent records a policy for the host. During the policy lifetime, later HTTP navigation to that host is rewritten to HTTPS before an HTTP connection is made.

Cybersecurity 21 Sep 2026 5 min read

HSTS Enforces HTTPS After a Host Policy Is Known

HSTS Enforces HTTPS After a Host Policy Is Known A redirect from HTTP to HTTPS moves a request onto TLS, but the first HTTP request still exists. If a browser starts with http://example.com, it can contact the HTTP endpoint before it receives the redirect. A network attacker positioned on that path can interfere before the browser reaches TLS. HTTP Strict Transport Security (HSTS), standardized in RFC 6797, changes later navigation behavior. A conforming user agent that receives a valid Strict-Transport-Security response over secure transport records an HTTPS-only policy for the host. While that policy remains active, an HTTP URL for the host is rewritten to HTTPS before an insecure request is sent.

Cybersecurity 21 Sep 2026 5 min read

Fetch Metadata Headers Filter Cross-Site Requests

Fetch Metadata Headers Filter Cross-Site Requests A web server often receives requests that look valid at the HTTP layer even when they originated from an unrelated site. Cookies may accompany those requests, and a state-changing endpoint can be exposed if its defenses treat every browser request as equally trustworthy. Fetch Metadata gives the server additional context. Supporting browsers attach Sec-Fetch-* request headers that describe the relationship between the initiator and target, the request mode, the destination, and whether navigation resulted from direct user activation. A server can use that context as an early resource-isolation gate.

Cybersecurity 21 Sep 2026 6 min read

CSP Nonces Bind Inline Scripts to Individual Responses

CSP Nonces Bind Inline Scripts to Individual Responses Inline JavaScript creates an awkward boundary for a strict Content Security Policy. A policy that allows every inline script with 'unsafe-inline' gives injected script blocks the same execution privilege as intended code. A nonce provides a narrower mechanism: the server generates an unpredictable value for one response, places that value in the policy, and attaches it only to script elements that are meant to run.

Cybersecurity 21 Sep 2026 5 min read

CSP frame-ancestors Restricts Page Embedding

CSP frame-ancestors Restricts Page Embedding Clickjacking does not require an attacker to replace the target application’s interface. A hostile page can place the real application inside a transparent or carefully positioned frame, then arrange decoy controls so a user’s click lands on an authenticated action in the framed page. The frame-ancestors directive in Content Security Policy moves the embedding decision to the response being framed. The target declares which ancestors are acceptable. A conforming browser checks the ancestor chain before allowing the protected resource to load in a nested browsing context.

Cybersecurity 21 Sep 2026 5 min read

Cross-Origin-Resource-Policy Controls no-cors Embedding

Cross-Origin-Resource-Policy Controls no-cors Embedding Web pages routinely embed resources without granting JavaScript direct access to their response bytes. Images, classic scripts, media, and other subresources can use no-cors request mode, where the browser permits forms of cross-origin loading while keeping the response opaque to script. That default is useful for the web, but a resource owner may need a tighter boundary. Cross-Origin-Resource-Policy (CORP) is an HTTP response header that tells the browser which origins or sites may consume a response through the policy’s no-cors path.

Cybersecurity 21 Sep 2026 6 min read

Cross-Origin-Opener-Policy Separates Window Relationships

Cross-Origin-Opener-Policy Separates Window Relationships A browser window can hold a reference to another top-level window. window.open() returns a WindowProxy, and an opened document may receive a window.opener reference. The same-origin policy restricts what cross-origin windows can inspect, but the relationship itself can still expose useful state and communication surfaces. Cross-Origin-Opener-Policy (COOP) adds a boundary around that relationship. The response header influences whether a top-level document remains in a compatible browsing context group (BCG) or moves into a new one. When policies require separate groups, references between opener and opened document are severed.

Cybersecurity 20 Sep 2026 5 min read

Subresource Integrity Pins Browser Execution to Expected Bytes

Subresource Integrity Pins Browser Execution to Expected Bytes A web page can fetch JavaScript and stylesheets from infrastructure outside the application’s deployment boundary. A CDN improves distribution, but the browser normally treats the response from the referenced URL as the resource the page requested. If that response changes unexpectedly, transport security alone does not tell the browser that the bytes differ from the version selected by the application operator. Subresource Integrity (SRI) adds a content check to that load. The page carries cryptographic metadata for an expected representation. A supporting browser hashes the fetched resource and accepts it only when the result satisfies the declared integrity metadata.

Cybersecurity 20 Sep 2026 6 min read

Session ID Rotation Closes the Pre-Authentication Session Gap

Session ID Rotation Closes the Pre-Authentication Session Gap A web application can assign a session before a user signs in. That anonymous session may hold a CSRF token, locale, shopping state, or other temporary data. Authentication changes the authority attached to the session: the server now treats requests carrying that session as belonging to an identified account. If the application keeps the same session identifier across that transition, a value established before authentication can become the handle for an authenticated session. Session fixation attacks target that continuity. The defensive boundary is the authentication event itself: preserve only the state that should survive, issue a fresh unpredictable identifier, and retire the old identifier.

Cybersecurity 20 Sep 2026 6 min read

SameSite Cookies Reduce Cross-Site Request Attachment

SameSite Cookies Reduce Cross-Site Request Attachment Cookie-based sessions rely on browser behavior that is both useful and security-sensitive: once a cookie matches a request’s domain, path, security, and other applicable rules, the browser can attach it without application code explicitly supplying the credential. That ambient behavior makes sessions convenient, but it also creates a channel through which a request initiated from another site can arrive with authentication state. The SameSite cookie attribute narrows that channel. It tells the browser whether a cookie may accompany requests whose site context differs from the cookie’s site. The control changes credential attachment at the browser boundary; it does not turn a state-changing endpoint into an authorized operation by itself.

Cybersecurity 20 Sep 2026 5 min read

SameSite Cookies Make Site Context Part of Session Delivery

SameSite Cookies Make Site Context Part of Session Delivery HTTP cookies are ambient credentials in many web applications. Once a browser stores a session cookie, matching requests can carry it automatically; application code does not have to attach the credential to every request. That convenience also creates a security problem: a page on another site may cause the browser to issue a request to the authenticated application. The SameSite cookie attribute adds request context to the browser’s delivery decision. A cookie can still match its domain, path, expiry, and transport requirements, yet be withheld because the request is cross-site. The control therefore changes where part of the session boundary is enforced: before the credential reaches the server.

Cybersecurity 20 Sep 2026 6 min read

Password Reset Links Need a Trusted Public Origin

Password Reset Links Need a Trusted Public Origin A password reset email often contains one of the most sensitive URLs an application creates. Possession of a valid reset token may be enough to establish a new credential for the associated account, so the destination embedded in that URL is part of the security boundary. A common implementation mistake is to construct the absolute reset URL from host information carried by the incoming HTTP request. Headers such as Host exist for request routing, and deployments behind proxies may also expose forwarded host or scheme metadata. Unless the application has explicitly established which intermediary is trusted and which values are valid, that request metadata is not a safe source of authority for a security-sensitive outbound link.

Cybersecurity 20 Sep 2026 5 min read

HSTS Pins HTTPS Policy to the Browser

HSTS Pins HTTPS Policy to the Browser Redirecting HTTP traffic to HTTPS is useful, but a redirect is still an HTTP response. A browser that starts with http://example.com has already sent an unauthenticated request before the server can answer with 301 or 308. An attacker able to modify that connection can suppress or replace the redirect. HTTP Strict Transport Security (HSTS) moves part of the transport policy into the browser. After receiving a valid Strict-Transport-Security header over HTTPS, a supporting browser remembers that the host requires secure transport for the declared lifetime. Later attempts to use HTTP for that host are upgraded locally before an HTTP request is sent.

Cybersecurity 20 Sep 2026 6 min read

Fetch Metadata Headers Gate Cross-Site Requests

Fetch Metadata Headers Gate Cross-Site Requests A web server often receives enough HTTP information to route a request but not enough to tell what browser context produced it. A GET might be a top-level navigation, an image load, or a JavaScript fetch. A POST might come from the application’s own page or from a form hosted on another site. Fetch Metadata adds browser-generated request headers that describe that context. Sec-Fetch-Site reports the relationship between the initiator and target, while Sec-Fetch-Mode, Sec-Fetch-Dest, and in some cases Sec-Fetch-User describe the request mode, destination, and user activation. A server can use those signals to reject request shapes that an endpoint has no reason to accept.

Cybersecurity 20 Sep 2026 5 min read

CSP Nonces Bind Script Execution to Each Response

CSP Nonces Bind Script Execution to Each Response Content Security Policy can restrict which scripts a browser executes after receiving a document. A nonce-based policy moves that decision away from a broad host allowlist: the server places a fresh unpredictable value in the response policy and copies that value only onto script elements it intends to authorize. The mechanism is narrow. A nonce does not sanitize HTML, prove that a script is benign, or repair an unsafe DOM API. It gives the browser an authorization token for selected script elements in one document response.

Cybersecurity 19 Sep 2026 4 min read

HSTS State Closes the First-Request Downgrade Window

HSTS State Closes the First-Request Downgrade Window A site can redirect every HTTP request to HTTPS and still expose a gap before that redirect arrives. The browser has already sent an HTTP request across the network. An active intermediary can alter that exchange, suppress the redirect, or keep the client on plaintext HTTP. HTTP Strict Transport Security (HSTS), defined by RFC 6797, changes where the decision occurs. After receiving a valid Strict-Transport-Security header over a secure connection, a conforming user agent records policy state for the host. A later HTTP navigation to that host is converted to HTTPS locally before the insecure request is emitted.

Cybersecurity 19 Sep 2026 6 min read

Fetch Metadata Headers Define a Server-Side Cross-Site Request Boundary

A browser can send an authenticated request to a site from a document hosted somewhere else. Cookies may accompany that request according to their cookie attributes, while the same-origin policy can still prevent the initiating page from reading the response. For a server, that distinction matters: blocking response access does not necessarily stop a cross-site request from reaching an endpoint. Fetch Metadata adds request context to this boundary. Supporting user agents attach Sec-Fetch-* request headers that describe relationships and request properties the server can evaluate before application logic performs a sensitive action. A policy can reject a request because it is cross-site, while preserving selected navigation or public-resource flows.

Cybersecurity 19 Sep 2026 6 min read

CSP Nonces Move Script Trust from Hostnames to Response Markup

CSP Nonces Move Script Trust from Hostnames to Response Markup A script policy based only on hostnames answers a coarse question: which network locations may supply JavaScript? That boundary becomes weak when an allowed origin hosts user-controlled files, JSONP-style endpoints, legacy script resources, or other content that was never intended to receive execution authority. A nonce-based Content Security Policy changes the unit of trust. Instead of granting execution authority to every script fetched from an approved host, the server places an unpredictable value in the policy and on the specific <script> elements authorized for that response. The browser checks that relationship before executing those elements.

Cybersecurity 19 Sep 2026 7 min read

CSP Nonces and strict-dynamic Shift Script Trust to the Bootstrap Boundary

A Content Security Policy can contain a long list of approved script hosts and still expose more execution authority than its author intended. A host source such as https://cdn.example.net authorizes matching script resources from that origin; it does not express which individual response or which application decision is trusted. When a permitted host serves user-controlled files, legacy JSONP endpoints, or another executable resource outside the application’s intended set, the host boundary can become too broad.

Cybersecurity 17 Sep 2026 7 min read

DNS Rebinding Preserves Web Origin While Changing Network Destination

DNS Rebinding Preserves Web Origin While Changing Network Destination A browser can load active content from a public server, keep that content in the same web origin, and later send requests bearing the same hostname to a private address. No origin tuple has changed. The network destination has. That mismatch is the core of DNS rebinding. Web origins are principally identified by scheme, host, and port, while DNS maps a hostname to network addresses outside that tuple. When a name controlled by an attacker resolves differently over time, origin checks and network-location checks can describe two distinct security boundaries.